25 Jun 2019

Vulnerability Details: SQL Injection in Author Chat

One of the changelog entries for the latest version of Author Chat is “Security fix”. In looking into what was done we found that the plugin still seems to be rather insecure and probably shouldn’t be used without the security of it being thoroughly reviewed and improved. It also looks to have other issues, since for example, we found that one of its database tables is only created if you activate the plugin for a second time.


[Read more]