Input validation vulnerability in Plg Novana *

The Plg Novana plugin for WordPress has a security vulnerability that makes it possible for unauthenticated attackers to gain access to sensitive information from the database. The vulnerability exists because the plugin does not properly escape user supplied parameters and does not prepare existing SQL queries enough. This leaves the plugin open to something called generic SQL Injection, which occurs when an attacker adds extra SQL queries to existing queries.

Detected in:

Plg Novana fixed vulnerable versions: >= * <= *

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.