Unauthenticated SQL Injection Vulnerability in Themify WooCommerce Product Filter Plugin
CVE-2024-6027
7.5HIGH
Summary
The article discusses a critical vulnerability, CVE-2024-6027, in the Themify WooCommerce Product Filter plugin for WordPress, allowing for unauthenticated SQL injection attacks. The vulnerability affects all versions up to 1.4.9. The potential impact includes the extraction of sensitive information from the database, and while there are no known exploits or ransomware attacks targeting this vulnerability, it is important for users to update to the latest version to safeguard their systems.
Affected Version(s)
Themify β WooCommerce Product Filter * <= 1.4.9
Get notified when SecurityVulnerability.io launches alerting π
Well keep you posted π§
News Articles
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
- π°
First article discovered by Cyber Security Informer
Vulnerability published
Vulnerability Reserved
Credit
Arkadiusz Hydzik