Input validation vulnerability in Amazon Product in a Post Plugin 3.5.3

The Amazon Product in a Post plugin for WordPress is vulnerable to a type of attack called generic SQL Injection in versions up to 3.5.2. This type of attack is possible because the plugin does not properly secure the user supplied parameter called ‘appip-cache-id’. This lack of security means that unauthenticated attackers can add additional SQL queries to existing queries that can be used to access sensitive information from the database.

Detected in:

Amazon Product in a Post Plugin open vulnerable versions: >= * < 3.5.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.