CVE-2024-11179

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Nov 20, 2024
Updated: Nov 21, 2024
CWE ID 89

Summary

CVE-2024-11179 is a newly disclosed vulnerability affecting the MStore API plugin for WordPress. This issue allows authenticated attackers, with Subscriber-level access and above, to inject SQL queries into the plugin via the 'status_type' parameter. Due to insufficient escaping and lack of preparation of user-supplied data, attackers can append malicious SQL commands to the existing queries. This vulnerability exposes sensitive information from the database. WordPress users must upgrade to a version beyond 4.15.7 to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share