SQL Injection Vulnerability in Webriderz Age Verification Plugin
CVE-2024-55979
8.5HIGH
Summary
CVE-2024-55979 identifies a critical SQL Injection vulnerability in the Webriderz Wr Age Verification plugin. This vulnerability allows attackers to manipulate SQL queries by injecting malicious SQL code. As a result, unauthorized access to sensitive data or executing arbitrary SQL commands can occur. The issue is present in all versions of the plugin up to and including version 2.0.0. It is imperative for users to update to a patched version to mitigate potential exploitation risks. Proper input validation and sanitization measures should be prioritized to prevent SQL injection vulnerabilities in web applications.
Affected Version(s)
Wr Age Verification <= 2.0.0
References
CVSS V3.1
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
LVT-tholv2k (Patchstack Alliance)