CVE-2024-47350

CVSS 3.1 Score 9.3 of 10 (high)

Details

Published Oct 6, 2024
Updated: Oct 7, 2024
CWE ID 89

Summary

CVE-2024-47350 is a newly disclosed SQL Injection vulnerability affecting YITH WooCommerce Ajax Search. The flaw, which allows for malicious SQL commands to be executed, can be exploited by attackers to gain unauthorized access to sensitive data or even take control of the affected system. The vulnerability exists in versions 2.8.0 and below of the plugin, and it arises due to the application's failure to properly neutralize special elements used in SQL commands. Successful exploitation of this issue could result in significant data breaches and undesirable system modifications. Users of YITH WooCommerce Ajax Search are strongly advised to update to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share