// For flags

CVE-2024-9186

Automation By Autonami < 3.3.0 - Unauthenticated SQLi

Severity Score

"-"
*CVSS v-

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit WordPress plugin before 3.3.0 does not sanitize and escape the bwfan-track-id parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

*Credits: y4ng0615, WPScan
CVSS Scores
Attack Vector
-
Attack Complexity
-
Privileges Required
-
User Interaction
-
Scope
-
Confidentiality
-
Integrity
-
Availability
-
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2024-09-25 CVE Reserved
  • 2024-11-14 CVE Published
  • 2024-11-14 CVE Updated
  • 2024-11-14 First Exploit
  • 2024-11-15 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Unknown
Search vendor "Unknown"
Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation
Search vendor "Unknown" for product "Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation"
< 3.3.0
Search vendor "Unknown" for product "Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation" and version " < 3.3.0"
en
Affected