Ajax Rating with Custom Login Vulnerable to SQL Injection
CVE-2024-49246
9.3CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 October 2024
What is CVE-2024-49246?
The Ajax Rating with Custom Login product by Anand23 is susceptible to an SQL Injection vulnerability due to improper neutralization of special elements used in SQL commands. This flaw allows attackers to execute arbitrary SQL queries, potentially compromising the database and exposing sensitive information. Versions up to and including 1.1 are affected, highlighting the need for immediate remediation to secure web applications against malicious SQL injection attacks.
Affected Version(s)
Ajax Rating with Custom Login 0 <= 1.1