Input validation vulnerability in Toolbox 1.4

The Toolbox theme for WordPress is vulnerable to a type of attack known as SQL Injection. This type of attack can be used to access sensitive information from a website’s database. In versions of the Toolbox theme up to and including 1.4, this is possible because the user supplied parameter is not properly escaped and the existing SQL query is not properly prepared, making it easy for unauthenticated attackers to add additional SQL queries into the existing query.

Detected in:

Toolbox open vulnerable versions: >= * <= 1.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.