|
|||
Rule General Information |
---|
Release Date: | 2024-07-10 | |
Rule Name: | WordPress Plugin Recall SQL Injection Vulnerability (CVE-2024-32709) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall: from n/a through 16.26.5. | |
Impact: | An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully. | |
Affected OS: | Windows, Linux, Others | |
Reference: | https://patchstack.com/database/vulnerability/wp-recall/wordpress-wp-recall-plugin-16-26-5-sql-injection-vulnerability?_s_id=cve |
|
Solutions |
---|
Refer to the announcement or patch by the vendor:https://wordpress.org/plugins/wp-recall/ |