CVE-2024-47350
CVSS 3.1 Score 9.3 of 10 (high)
Details
Summary
CVE-2024-47350 is a newly disclosed SQL Injection vulnerability affecting YITH WooCommerce Ajax Search. The flaw, which allows for malicious SQL commands to be executed, can be exploited by attackers to gain unauthorized access to sensitive data or even take control of the affected system. The vulnerability exists in versions 2.8.0 and below of the plugin, and it arises due to the application's failure to properly neutralize special elements used in SQL commands. Successful exploitation of this issue could result in significant data breaches and undesirable system modifications. Users of YITH WooCommerce Ajax Search are strongly advised to update to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.