plugin

Double Opt In For Download Vulnerabilities

2 known security issues reported for the Double Opt In For Download WordPress plugin. Most recent disclosed Jun 6, 2016.

1 critical 1 high

Running Double Opt In For Download on your site? Check whether your installed version is affected.

Scan your site free

Double Opt-In for Download <= 2.0.9 - SQL Injection

high

The Double Opt-In for Download Plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter in versions up to, and including, 2.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated at...

CVSS:
8.8
Affected:
up to 2.1.0
Fixed in:
2.1.0
Disclosed:
Jun 6, 2016

Double Opt-In for Download <= 2.0.8 - SQL Injection

critical

Multiple SQL injection vulnerabilities in the Double Opt-In for Download plugin before 2.0.9 for WordPress allow remote attackers to execute arbitrary SQL commands via the ver parameter to (1) class-doifd-download.php or (2) class-doifd-landing-page.php in public/includes/.

CVSS:
9.8
Affected:
up to 2.0.9
Fixed in:
2.0.9
Disclosed:
Nov 24, 2015

CVE-2015-7517 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database