Finalist Vulnerabilities
The Finalist WordPress plugin has 2 known security vulnerabilities, including 1 critical. The most recent was disclosed on October 14, 2013. Check whether your site runs an affected version below.
View Finalist on WordPress.orgSummary
Latest vulnerability disclosed on October 14, 2013.
Recommendation
WPSentry recommends extreme caution
Only run Finalist if it is updated to the latest patched release. This plugin has a history of 1 critical, potentially exploitable vulnerability. If you already use it, update immediately — or consider a safer alternative.
Is your site affected?
Run a free external scan to detect Finalist and 35+ other WordPress security checks — no login or plugin required.
Known Finalist vulnerabilities
- medium
Finalist (All Versions) - Cross-Site Scripting
Affected versions: <=*Disclosed October 14, 2013 - critical
Finalist (All Versions) - SQL Injection
Affected versions: <=*Disclosed March 25, 2013
How to stay protected
Update promptly
Keep Finalist on its latest release — most vulnerabilities are fixed in newer versions.
Scan regularly
Run an external scan after every update to catch outdated or vulnerable software early.
Monitor continuously
Enable monitoring to get alerted the moment a new issue affects your stack.
Related security concepts
Related fix guides
Sanitize input, escape output, patch vulnerable plugins, and add a Content-Security-Policy.
Patch vulnerable plugins and use $wpdb->prepare() for every query with user input.
Update everything, remove abandoned plugins, and check each against known vulnerabilities.