CVE-2024-13713

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Feb 21, 2025
Updated: Feb 25, 2025
CWE ID 89

Summary

CVE-2024-13713 is a vulnerability affecting the WPExperts Square For GiveWP plugin for WordPress. This issue allows authenticated attackers, with Subscriber-level access and above, to inject SQL queries through the 'post' parameter due to insufficient escaping and lack of query preparation. Consequently, attackers can extract sensitive information from the database by appending malicious SQL code to existing queries. Versions up to and including 1.3.1 are vulnerable to this SQL Injection attack.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share