Blind Time-Based SQL Injection Vulnerability in Cost Calculator Builder PRO Plugin for WordPress
CVE-2024-11939

7.5HIGH

Key Information:

Vendor
Stylemixthemes
Status
Cost Calculator Builder Pro
Vendor
CVE Published:
8 January 2025

Summary

The Cost Calculator Builder PRO plugin for WordPress suffers from a blind time-based SQL injection vulnerability due to improper handling of the 'data' parameter. This weakness affects all versions up to and including 3.2.15. Unsanitized input allows unauthenticated attackers to inject malicious SQL queries, potentially exposing sensitive data from the WordPress database. This issue arises from insufficient escaping of user-supplied input and inadequate preparation of SQL queries, posing a serious security risk for WordPress sites utilizing this plugin.

Affected Version(s)

Cost Calculator Builder PRO * <= 3.2.15

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Trương Hữu Phúc (truonghuuphuc)
.