Input validation vulnerability in Actionwear products sync 2.3.3

The plugin for WordPress that syncs with Actionwear products has a security issue called SQL Injection. This means that in versions up to 2.3.3, there is not enough protection for a certain part of the plugin that users can control, and the existing database search is not well-prepared. This makes it possible for people who are logged in and have at least subscriber access to add their own database searches, which can be used to get private information.

Detected in:

Actionwear products sync open vulnerable versions: >= * <= 2.3.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.