Input validation vulnerability in Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin 1.3.58

The Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin for WordPress is vulnerable to a security risk known as SQL Injection. This risk affects versions of the plugin up to, and including, 1.3.58. This happens because the plugin does not properly escape user-supplied information and does not prepare existing SQL queries securely. This means that attackers who are logged in can add SQL queries to existing ones, potentially allowing them to get sensitive information from the database.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.