WordPress · Wassup · CVE-2008-0520
**Name of the Vulnerable Software and Affected Versions**
WassUp plugin versions 1.4 through 1.4.3 for WordPress
**Description**
The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the `from date` or `to date` parameter to "spy.php".
**Recommendations**
For WassUp plugin versions 1.4 through 1.4.3, consider updating to a version that is not affected by this issue, as no specific fix is provided for these versions.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.