SQL Injection Vulnerability in Webriderz Age Verification Plugin
CVE-2024-55979

8.5HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
16 December 2024

Summary

CVE-2024-55979 identifies a critical SQL Injection vulnerability in the Webriderz Wr Age Verification plugin. This vulnerability allows attackers to manipulate SQL queries by injecting malicious SQL code. As a result, unauthorized access to sensitive data or executing arbitrary SQL commands can occur. The issue is present in all versions of the plugin up to and including version 2.0.0. It is imperative for users to update to a patched version to mitigate potential exploitation risks. Proper input validation and sanitization measures should be prioritized to prevent SQL injection vulnerabilities in web applications.

Affected Version(s)

Wr Age Verification <= 2.0.0

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LVT-tholv2k (Patchstack Alliance)
.