Unauthenticated SQL Injection Vulnerability in UsersWP Plugin for WordPress
CVE-2024-6265
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 29 June 2024
What is CVE-2024-6265?
The UsersWP plugin for WordPress has a vulnerability that arises from inadequate escaping of user input received via the ‘uwp_sort_by’ parameter. This flaw allows unauthenticated attackers to perform time-based SQL injection, leading to the possibility of injecting arbitrary SQL queries. Such an exploitation could result in unauthorized access to sensitive information stored in the database. All versions of the plugin up to and including 1.2.10 are affected, necessitating prompt action to secure the installation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress * <= 1.2.10
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved