RULE(RULE ID:338246)

Rule General Information
Release Date: 2024-07-10
Rule Name: WordPress Plugin Recall SQL Injection Vulnerability (CVE-2024-32709)
Severity:
CVE ID:
Rule Protection Details
Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall: from n/a through 16.26.5.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference: https://patchstack.com/database/vulnerability/wp-recall/wordpress-wp-recall-plugin-16-26-5-sql-injection-vulnerability?_s_id=cve
Solutions
Refer to the announcement or patch by the vendor:https://wordpress.org/plugins/wp-recall/