Secure Your Database from SQL Injection Vulnerabilities
CVE-2024-8621

9.9CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
25 September 2024

What is CVE-2024-8621?

The Daily Prayer Time plugin for WordPress has a security flaw allowing SQL Injection via the 'max_word' attribute of the 'quran_verse' shortcode. This vulnerability arises from inadequate escaping of user-supplied parameters and insufficient preparation of existing SQL queries. Authenticated attackers with Contributor-level access or higher can exploit this issue to inject additional SQL queries. The exploitation may lead to unauthorized access to sensitive data stored within the database, putting user and site information at risk. Immediate action is advised to mitigate potential exploits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Daily Prayer Time * <= 2024.08.26

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

.