CVE-2024-13532
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Feb 12, 2025
Updated: Feb 25, 2025
CWE ID 89
Summary
CVE-2024-13532: A critical SQL Injection vulnerability has been identified in the Small Package Quotes – Purolator Edition plugin for WordPress. This issue, affecting versions up to 3.6.4, stems from insufficient escaping of user-supplied data and a lack of preparation on existing SQL queries. Unauthenticated attackers can exploit this vulnerability by appending additional SQL queries, granting them access to sensitive information in the database. WordPress users are urged to update the plugin as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share