CVE-2024-13726
CVSS 3.1 Score 8.6 of 10 (high)
Details
Published Feb 17, 2025
Updated: Feb 19, 2025
Summary
CVE-2024-13726 refers to a vulnerability in the Coder WordPress plugin. This issue allows unauthenticated users to injectSQL code due to insufficient sanitization and escaping of a parameter used in a SQL statement via an available AJAX action. The vulnerability could potentially enable attackers to access, modify, or delete sensitive information stored in the affected WordPress database. Users running versions of the Coder plugin prior to 1.3.5 are advised to update as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share