SQL injection vulnerability
-
I’ve been informed by my site host (WP Engine) that version 2.26.1 of Relevanssi is vulnerable to a SQL injection attack. To quote, “The plugin contains a vulnerability wherein unauthenticated visitors could inject SQL statements into WordPress. A SQL injection could allow an attacker to gain control of your site.”
They referred to this page on Patchstack to support the concern: https://patchstack.com/database/wordpress/plugin/relevanssi-premium/vulnerability/wordpress-relevanssi-premium-plugin-2-27-4-unauthenticated-sql-injection
Is this true?
And if so, how can I update? Oddly in my WordPress dashboard, I don’t have the option to update the plug-in to a newer version. I am currently running 2.26.1, the same one mentioned above.
The topic ‘SQL injection vulnerability’ is closed to new replies.