Input validation vulnerability in WP eCommerce 3.11.4

The WP eCommerce plugin for WordPress is vulnerable to a type of attack called SQL Injection. This is where a malicious user can add extra code to a query that can be used to gain access to sensitive information. Versions of the plugin up to and including 3.11.3 are vulnerable to this type of attack because they do not properly escape the user supplied data and the existing SQL query was not well prepared.

Detected in:

WP eCommerce open vulnerable versions: >= * < 3.11.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.