CVE-2024-13321
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Mar 14, 2025
Updated: Mar 21, 2025
CWE ID 89
Summary
CVE-2024-13321 is a vulnerability affecting the AnalyticsWP plugin for WordPress. The issue lies in the handle_get_stats() function, which fails to implement adequate authorization checks on the 'custom_sql' parameter. As a result, unauthenticated attackers can inject additional SQL queries into existing ones, potentially gaining access to sensitive information stored in the database. This vulnerability can be exploited without requiring any valid authentication credentials. Versions of the plugin up to and including 2.0.0 are susceptible to this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.