CVE-2024-13726
HIGH
Published 2025-02-17T06:00:09.727Z
Actions:
CVSS Score
V3.1
8.6
/10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Base Score Metrics
Exploitability: N/A
Impact: N/A
Attack Vector Metrics
Impact Metrics
Description
The Coder WordPress plugin through 1.3.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
Available Exploits
Themes Coder Ecommerce <= 1.3.4 - SQL Injection
The Themes Coder Ecommerce WordPress plugin through 1.3.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
ID: CVE-2024-13726
Author: s4e-io
High
Related News
No news articles found for this CVE.
Affected Products
Affected Versions:
Published: 2025-02-17T06:00:09.727Z
Last Modified: 2025-02-19T21:42:06.052Z
Copied to clipboard!