Input validation vulnerability in FireStorm Professional Real Estate Plugin 2.06.03

The FireStorm Professional Real Estate Plugin, a plugin for WordPress, is vulnerable to SQL Injection. This means that attackers who do not have permission to access certain information on the website can still gain access to that information. This vulnerability is present in versions of the plugin up to and including 2.06.03. It is caused by an inadequate escape of the user supplied parameter, and an insufficiently prepared SQL query. This allows attackers to append additional SQL queries to the existing ones, thus obtaining sensitive information from the database.

Detected in:

FireStorm Professional Real Estate Plugin fixed vulnerable versions: >= * <= 2.06.03

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.