Input validation vulnerability in Most And Least Read Posts Widget 2.5.17

The Most And Least Read Posts Widget plugin for WordPress is vulnerable to malicious code being inserted into it. All versions of the plugin up to 2.5.17 (not including 2.5.17) are affected due to a lack of protection from user input, and inadequate protection from existing SQL queries. This means that someone with contributor access or above could add extra SQL queries to existing queries, which could be used to steal sensitive data from the database.

Detected in:

Most And Least Read Posts Widget fixed vulnerable versions: >= * < 2.5.17

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.