Input validation vulnerability in Email Before Download 3.4

The Email Before Download plugin for WordPress, up to and including version 3.4, has a vulnerability that can lead to the extraction of sensitive information from the database. This vulnerability occurs because the plugin does not properly escape certain parameters that are supplied by the user, and does not properly prepare existing SQL queries. This allows an unauthenticated attacker to add additional SQL queries to existing queries.

Detected in:

Email Before Download fixed vulnerable versions: >= * <= 3.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.