CVE-2024-47338
CVSS 3.1 Score 7.6 of 10 (high)
Details
Published Oct 6, 2024
Updated: Oct 7, 2024
CWE ID 89
Summary
CVE-2024-47338 is a newly disclosed SQL Injection vulnerability affecting WPExperts Square For GiveWP. Hackers can exploit this issue by introducing malicious SQL statements to the application, leading to unauthorized data access or modification. The flaw, which exists from version n/a through 1.3, can pose significant risks to WordPress sites that utilize this plugin. System administrators are advised to update WPExperts Square For GiveWP to the latest, secure version as soon as possible to mitigate these risks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.