WordPress WassUp Plugin “to_date” SQL Injection

Application: WordPress WassUp Plugin
Affected Version: 1.4 to 1.4.3 and other versions.
Vendor’s URL: http://www.wpwp.org/
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Update to version 1.4.3a.
http://wordpress.org/extend/plugins/wassup/