Input validation vulnerability in Leaflet Maps Marker Pro 2.4

The Leaflet Maps Marker plugin for WordPress, which lets you create maps using Google Maps, OpenStreetMap, and Bing Maps, is vulnerable to a type of attack called SQL Injection in versions 2.3.1 and below. This type of attack happens when an attacker is able to add extra instructions to a query that can be used to get sensitive information from the database, which happens because the plugin does not escape any user-supplied parameters and does not properly prepare the existing SQL query.

Detected in:

Leaflet Maps Marker Pro fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.