CVE-2024-3552
June 13, 2024, 6:36 p.m.
Tags
Product(s) Impacted
Web Directory Free WordPress plugin
- before 1.7.0
Description
The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection with different techniques like UNION, Time-Based and Error-Based.
Weaknesses
Date
Published: June 13, 2024, 6:15 a.m.
Last Modified: June 13, 2024, 6:36 p.m.
Status : Awaiting Analysis
CVE has been recently published to the CVE List and has been received by the NVD.
More infoSource
contact@wpscan.com
References
https://wpscan.com/
contact@wpscan.com