Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Click & Pledge Connect Plugin allows SQL Injection. This issue affects Click & Pledge Connect Plugin: from 2.24080000 through WP6.6.1.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
2.24080000 (custom)
Credits
João Pedro S Alcântara (Kinorth) (Patchstack Alliance)
References
patchstack.com/...-6-1-sql-injection-vulnerability?_s_id=cve