Input validation vulnerability in WP-EMail 2.67.2

The WP-Email Plugin for WordPress is vulnerable to an attack called SQL Injection. This attack can be used to gain access to sensitive information in the database. It affects versions of the plugin before 2.67.2. Attackers can use the ‘last_emailed’ parameter, which has not been escaped properly, to add additional SQL queries to the existing ones and gain access. It is important to make sure that you are running the latest version of the WP-Email Plugin to avoid this vulnerability.

Detected in:

WP-EMail fixed vulnerable versions: >= * < 2.67.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.