CVE-2024-12635

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Dec 21, 2024
Updated: Feb 28, 2025
CWE ID 89

Summary

CVE-2024-12635 is a vulnerability affecting the WP Docs plugin for WordPress. It allows authenticated attackers with Subscriber-level access and above to inject SQL queries through the 'dir_id' parameter due to insufficient escaping and inadequate query preparation. This can result in the extraction of sensitive information from the database. The vulnerability was partially addressed in version 2.2.0, but earlier versions remain affected.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share