SQL Injection Vulnerability Affects WordPress Tooltips
CVE-2024-30243

8.5HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
28 March 2024

Summary

A vulnerability exists in Tomas WordPress Tooltips due to improper neutralization of special elements utilized in SQL commands, commonly referred to as SQL Injection. This flaw allows for unauthorized input into SQL queries, which can be exploited by attackers to manipulate database interactions. The issue has been identified in the versions prior to 9.4.5, posing a risk to websites utilizing the affected plugin. Administrators of affected installations are strongly recommended to update to the latest version to mitigate potential exploitation of this flaw.

Affected Version(s)

WordPress Tooltips < 9.4.5

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yudistira Arya (Patchstack Alliance)
.