CVE-2024-3265
WP Advanced Search <= 1.1.6 - Admin+ SQL Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The Advanced Search WordPress plugin through 1.1.6 does not properly escape parameters appended to an SQL query, making it possible for users with the administrator role to conduct SQL Injection attacks in the context of a multisite WordPress configurations.
El complemento Advanced Search de WordPres hasta la versión 1.1.6 no escapa correctamente a los parámetros agregados a una consulta SQL, lo que hace posible que los usuarios con función de administrador realicen ataques de inyección SQL en el contexto de configuraciones de WordPress multisitio.
The Advanced Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data parameter in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-04-03 CVE Reserved
- 2024-04-04 CVE Published
- 2024-04-26 EPSS Updated
- 2024-05-26 First Exploit
- 2024-08-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/zcrosman/cve-2024-32651 | 2024-05-26 | |
https://wpscan.com/vulnerability/ecb74622-eeed-48b6-a944-4e3494d6594d | 2024-08-01 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Unknown Search vendor "Unknown" | Advanced Search Search vendor "Unknown" for product "Advanced Search" | <= 1.1.6 Search vendor "Unknown" for product "Advanced Search" and version " <= 1.1.6" | en |
Affected
|