CVE-2024-47338

CVSS 3.1 Score 7.6 of 10 (high)

Details

Published Oct 6, 2024
Updated: Oct 7, 2024
CWE ID 89

Summary

CVE-2024-47338 is a newly disclosed SQL Injection vulnerability affecting WPExperts Square For GiveWP. Hackers can exploit this issue by introducing malicious SQL statements to the application, leading to unauthorized data access or modification. The flaw, which exists from version n/a through 1.3, can pose significant risks to WordPress sites that utilize this plugin. System administrators are advised to update WPExperts Square For GiveWP to the latest, secure version as soon as possible to mitigate these risks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share