Conversation
supportThe plugin is vulnerable to SQL Injection via the ‘attribute_value_filter’ parameter.
Hi @mehrazmorshed Thank you for bringing this to our attention. We acknowledge the issue you’ve reported regarding a potential SQL Injection vulnerability via the attribute_value_filter parameter in our plugin. Our development team is actively investigating this on our end, and we’re treating it with the highest priority. A fix will be included in an upcoming release, which we aim to make available soon. Please feel free to reach out if you have any additional information or concerns in the meantime.
Thanks for the update.
Hi @mehrazmorshed Thank you for bringing this to our attention. We acknowledge the issue you’ve reported regarding a potential SQL Injection vulnerability via the attribute_value_filter parameter in our plugin. Our development team is actively investigating this on our end, and we’re treating it with the highest priority. A fix will be included in an upcoming release, which we aim to make available soon. Please feel free to reach out if you have any additional information or concerns in the meantime.
Thanks for the update.