Input validation vulnerability in Message ticker 9.2

The Message ticker plugin for WordPress is not secure in versions up to 9.2. It is possible for someone with subscriber-level permissions or higher to access information from the database that should not be visible. This is done by adding extra SQL queries to the existing ones, which is made possible by the plugin not escaping the user-supplied parameter and not sufficiently preparing the SQL query.

Detected in:

Message ticker open vulnerable versions: >= * <= 9.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.