CVE-2024-13184
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Jan 18, 2025
CWE ID 89
Summary
CVE-2024-13184 is a vulnerability affecting the WP Extended plugin for WordPress, specifically its Login Attempts module. This issue arises from insufficient escaping of user-supplied parameters and a lack of sufficient preparation of SQL queries. Consequently, unauthenticated attackers can inject additional SQL queries into existing ones, potentially extracting sensitive information from the database through time-based SQL Injection attacks. Versions up to and including 3.0.12 are vulnerable.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.