CVE-2024-30489
CVSS 3.1 Score 8.5 of 10 (high)
Details
Published Mar 31, 2024
Updated: Apr 1, 2024
CWE ID 89
Summary
CVE-2024-30489 denotes a vulnerability in the WP Cost Estimation & Payment Forms Builder plugin for WordPress. This issue involves an SQL Injection vulnerability where special characters in user input are not properly neutralized. As a result, an attacker could potentially manipulate SQL commands to gain unauthorized access to sensitive data or modify it. The affected versions of the plugin range from its initial release to 10.1.75.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.