Input validation vulnerability in WP-PManager 1.2

The WP-PManager plugin for WordPress has a security vulnerability that allows hackers to access sensitive information from the database. This vulnerability exists in all versions up to 1.2 and is caused by inadequate precautions on the ‘id’ parameter and existing SQL query. Attackers with Administrator-level access or higher can add their own SQL queries to the existing ones, making it easy to extract sensitive data.

Detected in:

WP-PManager open vulnerable versions: >= * <= 1.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.