CVE-2024-54280

CVSS 3.1 Score 9.3 of 10 (high)

Details

Published Dec 16, 2024
CWE ID 89

Summary

CVE-2024-54280 is a newly disclosed SQL Injection vulnerability affecting Iqonic Design's WPBookit plugin. The issue arises from improper handling of special elements in SQL commands, granting attackers the ability to inject malicious code into a database. This vulnerability impacts WPBookit versions from n/a through 1.6.0, posing a significant risk to websites using this plugin. Successful exploitation could lead to unauthorized access, data theft, or system compromise. It is crucial for affected organizations to update their WPBookit plugin as soon as a patch becomes available to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share