SQL injection vulnerability in the Landing Pages plugin 1.2.3, before 20131009, and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the "post" parameter to index.php.
https://exchange.xforce.ibmcloud.com/vulnerabilities/87803
https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-6071
http://www.securityfocus.com/bid/62942
http://wordpress.org/plugins/landing-pages/changelog