Beveiligingsadvies

CVE-2024-3265

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-04-25 21:25:07
Laatst bijgewerkt 2024-08-01 20:05:08
Toegewezen door WPScan
CVSS-score 4.7
Status PUBLISHED

Beschrijving

The Advanced Search WordPress plugin through 1.1.6 does not properly escape parameters appended to an SQL query, making it possible for users with the administrator role to conduct SQL Injection attacks in the context of a multisite WordPress configurations.