Injection Guard

Injection Guard has 6 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2026; all 6 are fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 1 high. 2023 was the busiest year with 4 disclosures.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 2 of the records (33%). Other recurring categories include Cross-Site Scripting, Missing Authorization.

Every one of the 6 issues recorded for Injection Guard has a vendor fix available, so running the current release closes all known holes.

4 independent researchers contributed these findings, most of them (2) reported by Darius Sveikauskas. Injection Guard is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage100%
Open

0

Fixed

6

Get automatic notifications for all Injection Guard vulnerabilities before they are exploited.

Highest severity on recordCVSS 7.2CVE-2026-3368

Injection Guard <= 1.2.9 - Unauthenticated Stored Cross-Site Scripting via Query Parameter Name

Read the full analysis

Vulnerability Records

6 records
Injection Guard banner
Latestv1.3.1

Injection Guard

Fahad Mahmood

Author

Fahad Mahmood

5.0(5)
100/100
Last Updated
2026-07-02 (2mo ago)
Active Installs
1,000+
Downloads
36,406
Requires WP
3.0+
Requires PHP
7.0+
Tested up to
WP 7.0.4
Created
2014-02-21 (13y ago)

Author: Fahad Mahmood Project URI: https://www.androidbubbles.com/extends/wordpress/plugins/injection-guard License: GPL v3 Injection Guard is a WordPress plugin designed to block malicious query string attacks and suspicious URL parameters. It logs all incoming attempts, blocks harmful parameters, and adds extra security intelligence to your WordPress admin—like user session tracking and capability audit. The plugin uses the ig_ prefix for database keys and functions, follows WordPress coding standards, and supports multiple languages. It’s compatible with pretty permalinks and helps in securing your site from automated bots and manual attacks. Method A (Admin Panel) Login to WordPress Admin > Plugins > Add New > Upload Plugin Upload the ZIP file and activate the plugin Go to Settings > IG Settings and click “Save Settings” Method B (Manual Upload) Download and unzip the plugin package Upload the folder to /wp-content/plugins/injection-guard/ Activate the plugin from the WordPress Dashboard Visit Settings > IG Settings to configure Features Logs all unique query strings attempting to penetrate your website Blocks malicious or unknown query parameters Tracks login, logout, session start and duration per user Capability audit report for all WordPress users Multi-language support (FR, DE, ES) Bootstrap-based admin UI and dashboard License This plugin is free software licensed under the GNU GPL v2 or later. You should have received a copy of the GNU General Public License along with this plugin. If not, see http://www.gnu.org/licenses/gpl-2.0.html.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C