SQL Injection Vulnerability in Passwords Manager Plugin for WordPress
CVE-2024-12613
7.5HIGH
What is CVE-2024-12613?
The Passwords Manager plugin for WordPress is susceptible to SQL Injection due to improper escaping of the $wpdb->prefix value in multiple AJAX functions in all versions up to and including 1.4.8. This flaw arises from a lack of adequate preparation for user-supplied parameters within existing SQL queries. As a result, unauthenticated attackers can inject additional SQL queries into vulnerable endpoints, potentially allowing them to retrieve sensitive information from the database.
Affected Version(s)
Passwords Manager * <= 1.4.8