The 404 Solution WordPress plugin before 2.35.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admins.
Metrics
Affected Vendors & Products
References
History
Mon, 26 Aug 2024 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2024-03-11T17:56:05.763Z
Updated: 2024-08-26T18:17:29.237Z
Reserved: 2024-01-30T13:26:45.932Z
Link: CVE-2024-1068
Vulnrichment
Updated: 2024-08-01T18:26:30.460Z
NVD
Status : Awaiting Analysis
Published: 2024-03-11T18:15:17.847
Modified: 2024-11-21T08:49:43.460
Link: CVE-2024-1068
Redhat
No data.