← Back

CVE-2024-9156

nvd nist
Published: Oct 10, 2024Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

The TI WooCommerce Wishlist WordPress plugin through 2.8.2 is vulnerable to SQL Injection due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Affected (1)

Ti Woocommerce Wishlist
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.8.2

References (1)

Source: contact@wpscan.com
ExploitThird Party Advisory

Timeline

No history available yet.