The WPDating WordPress plugin before 7.4.0 does not properly escape user input before concatenating it to certain SQL queries, leading to multiple SQL injection vulnerabilities exploitable by unauthenticated users
Name | Vendor | Start Version | End Version |
---|---|---|---|
Wpdating | Digital_product_labs | * | 7.1.9 (including) |