Description
WordPress Plugin Plugmatter Optin Feature Box is prone to multiple SQL injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. WordPress Plugin Plugmatter Optin Feature Box version 2.0.13 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.1.18 or latest
References
http://cinu.pl/research/wp-plugins/mail_ec951d52aa603c9caaca8c7005b84004.html
https://wordpress.org/plugins/plugmatter-optin-feature-box-lite/changelog/
Related Vulnerabilities
WordPress Plugin iThemes Security (formerly Better WP Security) Cross-Site Scripting (3.2.4)
WordPress Plugin Donation Block For PayPal Cross-Site Scripting (2.0.0)
WordPress Plugin EDD Favorites Cross-Site Scripting (1.0.6)
WordPress Plugin BuddyPress 'page' Parameter SQL Injection (1.5.4)
WordPress Plugin miniOrange Discord Integration Security Bypass (2.1.5)