by @the0z1
06 May 2024

Understanding and exploiting unauthenticated arbitrary SQL execution in WordPress Automatic Plugin (CVE 2024-27956)

by @the0z1
06 May 2024

Understanding and exploiting unauthenticated arbitrary SQL execution in WordPress Automatic Plugin (CVE 2024-27956)

CVEs

9.9 Critical Severity

Screenshots from the blog posts

images/clvryah84o0uq1jn93soohf1b.jpgimages/clvryah84o0uq1jn93soohf1b.jpg

Summary

CVE-2024-29756: Unauthenticated users can inject SQL queries in WordPress Automatic Plugin pre-3.92.1, posing serious security risks.

Description

@the0z1

2 posts

Total vcoins

0

Comments (0)