Input validation vulnerability in GravityWP – Merge Tags 1.4.4

The GravityWP – Merge Tags plugin for WordPress has a security issue in versions 1.4.4 and below. This vulnerability allows attackers to access and run any files on the server without being logged in, which means they can run any PHP code in those files. This can be used to get around security measures, get confidential information, or run code in situations where only certain types of files, like images, are normally allowed to be uploaded and used.

Detected in:

GravityWP – Merge Tags fixed vulnerable versions: >= * <= 1.4.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.