The Top 10 – Popular posts WordPress plugin, up to version 2.4.3, has a vulnerability that allows people with admin level access to extract sensitive information from the database. This happens because the plugin does not properly escape the user supplied parameter or properly prepare the existing SQL query, making it possible for attackers to append additional SQL queries.