CVE-2024-13531

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Feb 12, 2025
Updated: Feb 20, 2025
CWE ID 89

Summary

CVE-2024-13531: A vulnerability in the ShipEngine Shipping Quotes plugin for WordPress allows unauthenticated attackers to inject SQL queries through the 'edit_id' parameter. This issue arises due to insufficient escaping of user-supplied data and inadequate preparation of existing SQL queries. Consequently, attackers can append malicious queries to extract sensitive information from the database. WordPress users are advised to update the plugin as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share