SQL Injection Flaw in Webriderz Age Verification Plugin
CVE-2024-55980
Key Information:
- Vendor
- WordPress
- Status
- Vendor
- CVE Published:
- 16 December 2024
Badges
Summary
CVE-2024-55980 is a critical SQL Injection vulnerability discovered in the Webriderz Wr Age Verification plugin. This flaw stems from improper neutralization of special characters used within SQL commands, which can allow an attacker to manipulate SQL queries. The vulnerability affects all versions of Wr Age Verification up to 2.0.0, potentially leading to unauthorized access to sensitive data or even full database compromise. It is crucial for users of this plugin to implement available security patches and remove the vulnerable versions to mitigate these risks.
Affected Version(s)
Wr Age Verification <= 2.0.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved