SQL Injection Vulnerability in Instant Appointment Plugin for WordPress
CVE-2024-54361
9.3CRITICAL
Summary
The Instant Appointment plugin for WordPress, developed by Outstrip, is susceptible to a critical SQL Injection vulnerability (CVE-2024-54361) due to improper neutralization of special elements used in SQL commands. This flaw allows attackers to manipulate database queries by injecting malicious SQL code, endangering sensitive data and potentially compromising the entire site. The vulnerability affects all versions of Instant Appointment from n/a through 1.2, posing a significant risk to users. It is crucial for website administrators to promptly update or secure their installations to mitigate this risk.
Affected Version(s)
Instant Appointment <= 1.2
References
CVSS V3.1
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
LVT-tholv2k (Patchstack Alliance)