SQL Injection Vulnerability in MotoPress Timetable Plugin Affects Sensitive Data
CVE-2024-3342
9.9CRITICAL
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 27 April 2024
What is CVE-2024-3342?
The Timetable and Event Schedule by MotoPress plugin for WordPress is susceptible to SQL Injection through the 'events' attribute of the 'mp-timetable' shortcode. This vulnerability exists in all versions up to and including 2.4.11 due to inadequate escaping of user-supplied parameters and insufficient safeguards in the SQL query construction. Authenticated attackers with contributor-level access can exploit this vulnerability to insert additional SQL queries, potentially leading to the unauthorized extraction of sensitive data from the database.
Affected Version(s)
Timetable and Event Schedule by MotoPress * <= 2.4.11