The 404 Solution WordPress plugin before 2.35.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admins.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 01 May 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ajexperience
Ajexperience 404 Solution |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:ajexperience:404_solution:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Ajexperience
Ajexperience 404 Solution |
Mon, 26 Aug 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-26T18:17:29.237Z
Reserved: 2024-01-30T13:26:45.932Z
Link: CVE-2024-1068
Updated: 2024-08-01T18:26:30.460Z
Status : Analyzed
Published: 2024-03-11T18:15:17.847
Modified: 2025-05-01T00:04:20.950
Link: CVE-2024-1068
No data.
OpenCVE Enrichment
No data.
Weaknesses