CVE-2024-13531
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Feb 12, 2025
Updated: Feb 20, 2025
CWE ID 89
Summary
CVE-2024-13531: A vulnerability in the ShipEngine Shipping Quotes plugin for WordPress allows unauthenticated attackers to inject SQL queries through the 'edit_id' parameter. This issue arises due to insufficient escaping of user-supplied data and inadequate preparation of existing SQL queries. Consequently, attackers can append malicious queries to extract sensitive information from the database. WordPress users are advised to update the plugin as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share