SQL Injection Vulnerability in VibeThemes VibeBP Plugin
CVE-2024-56039

9.3CRITICAL

Key Information:

Vendor
WordPress
Status
Vendor
CVE Published:
31 December 2024

Summary

A vulnerability exists in the VibeBP plugin developed by VibeThemes, which is related to improper neutralization of special elements used in SQL commands, leading to potential SQL Injection attacks. This flaw allows attackers to manipulate database queries and execute malicious SQL statements, potentially compromising the integrity and confidentiality of web application data. The affected version of VibeBP is any version prior to 1.9.9.7.7, emphasizing the critical need for users to update their installations to safeguard against these exploitation risks.

Affected Version(s)

VibeBP < 1.9.9.7.7

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad (Patchstack)
.