SQL Injection Vulnerability Affects WP-Recall
CVE-2024-32710

8.5HIGH

Key Information:

Vendor
WordPress
Status
Vendor
CVE Published:
24 April 2024

Summary

A vulnerability exists in the WP-Recall plugin developed by Plechev Andrey, primarily due to the improper neutralization of special elements used in SQL commands, which can lead to SQL Injection attacks. This weakness affects versions from n/a through 16.26.5, making it crucial for users running these versions to take steps to mitigate potential exploits. Attackers can leverage this vulnerability to execute arbitrary SQL queries, compromising the security and integrity of the WordPress site. It is imperative for website administrators to ensure timely updates and apply security patches to protect against this and future vulnerabilities.

Affected Version(s)

WP-Recall <= 16.26.5

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LVT-tholv2k (Patchstack Alliance)
.