Information leakage vulnerability in OpenInviter for WordPress 1.7.0

The OpenInviter for WordPress plugin, used in WordPress websites, had a security vulnerability in versions up to, and including, 1.7.0. This vulnerability could allow unauthenticated attackers to view sensitive data from site visitors, such as emails and passwords, without the visitor’s knowledge. This sensitive data was not encrypted, so attackers could view it in plain text, including emails and passwords from providers like Yahoo, Gmail, Hotmail, AOL, and more.

Detected in:

OpenInviter for WordPress open vulnerable versions: >= * <= 1.7.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.