CVE-2024-13230
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Jan 21, 2025
CWE ID 89
Summary
CVE-2024-13230: The WordPress plugin Super Socializer, versions up to 7.14, is susceptible to a Limited SQL Injection vulnerability. This issue stems from insufficient escaping on the user-supplied 'SuperSocializerKey' parameter, combined with a lack of proper preparation of existing SQL queries. Consequently, unauthenticated attackers can manipulate the queries to extract sensitive user metadata from the database. This poses a significant risk to sites using this plugin and should be addressed with an immediate update to a patched version.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.