The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit WordPress plugin before 3.3.0 does not sanitize and escape the bwfan-track-id parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 15 May 2025 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89
CPEs cpe:2.3:a:funnelkit:funnelkit_automations:*:*:*:*:*:wordpress:*:*

Fri, 15 Nov 2024 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Funnelkit
Funnelkit funnelkit Automations
CPEs cpe:2.3:a:funnelkit:funnelkit_automations:-:*:*:*:*:wordpress:*:*
Vendors & Products Funnelkit
Funnelkit funnelkit Automations
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 Nov 2024 06:15:00 +0000

Type Values Removed Values Added
Description The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit WordPress plugin before 3.3.0 does not sanitize and escape the bwfan-track-id parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks
Title Automation By Autonami < 3.3.0 - Unauthenticated SQLi
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-11-15T19:27:37.434Z

Reserved: 2024-09-25T19:36:54.377Z

Link: CVE-2024-9186

cve-icon Vulnrichment

Updated: 2024-11-15T19:25:41.569Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-14T06:15:07.223

Modified: 2025-05-15T16:28:08.107

Link: CVE-2024-9186

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.