CVE-2024-1776

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Feb 23, 2024

Summary

CVE-2024-1776 is a SQL Injection vulnerability affecting the Contact Form 7 plugin for WordPress. The vulnerability exists in all versions up to and including 1.1.1, due to insufficient escaping and preparation of user-supplied parameters in the 'form-id' parameter. This vulnerability allows authenticated attackers with administrator-level access or higher to insert additional SQL queries into existing queries, potentially extracting sensitive information from the database. The risk score for this vulnerability is 26, with a base severity of HIGH and an exploitability score of 1.2. The impact includes high integrity and confidentiality impacts, as well as a high availability impact. Remediation steps should be taken promptly to mitigate the risk posed by this vulnerability.

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2024-1776 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options