Blind Time-Based SQL Injection Vulnerability in Cost Calculator Builder PRO Plugin for WordPress
CVE-2024-11939
7.5HIGH
Key Information:
- Vendor
- Stylemixthemes
- Status
- Cost Calculator Builder Pro
- Vendor
- CVE Published:
- 8 January 2025
Summary
The Cost Calculator Builder PRO plugin for WordPress suffers from a blind time-based SQL injection vulnerability due to improper handling of the 'data' parameter. This weakness affects all versions up to and including 3.2.15. Unsanitized input allows unauthenticated attackers to inject malicious SQL queries, potentially exposing sensitive data from the WordPress database. This issue arises from insufficient escaping of user-supplied input and inadequate preparation of SQL queries, posing a serious security risk for WordPress sites utilizing this plugin.
Affected Version(s)
Cost Calculator Builder PRO * <= 3.2.15
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Trương Hữu Phúc (truonghuuphuc)