SQL Injection Vulnerability Affects WordPress Tooltips
CVE-2024-30243
8.5HIGH
Summary
A vulnerability exists in Tomas WordPress Tooltips due to improper neutralization of special elements utilized in SQL commands, commonly referred to as SQL Injection. This flaw allows for unauthorized input into SQL queries, which can be exploited by attackers to manipulate database interactions. The issue has been identified in the versions prior to 9.4.5, posing a risk to websites utilizing the affected plugin. Administrators of affected installations are strongly recommended to update to the latest version to mitigate potential exploitation of this flaw.
Affected Version(s)
WordPress Tooltips < 9.4.5
References
CVSS V3.1
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Yudistira Arya (Patchstack Alliance)