SQL Injection Vulnerability in Instant Appointment Plugin for WordPress
CVE-2024-54361
9.3CRITICAL
What is CVE-2024-54361?
The Instant Appointment plugin for WordPress, developed by Outstrip, is susceptible to a critical SQL Injection vulnerability (CVE-2024-54361) due to improper neutralization of special elements used in SQL commands. This flaw allows attackers to manipulate database queries by injecting malicious SQL code, endangering sensitive data and potentially compromising the entire site. The vulnerability affects all versions of Instant Appointment from n/a through 1.2, posing a significant risk to users. It is crucial for website administrators to promptly update or secure their installations to mitigate this risk.
Affected Version(s)
Instant Appointment <= 1.2