Application: WordPress WassUp Plugin
Affected Version: 1.4 to 1.4.3 and other versions.
Vendor’s URL: http://www.wpwp.org/
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Update to version 1.4.3a.
http://wordpress.org/extend/plugins/wassup/
