PT-2024-15500 · WordPress · Fancy Product Designer

Ivan Spiridonov

·

Published

2024-03-18

·

Updated

2024-08-08

·

CVE-2024-0365

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions The Fancy Product Designer WordPress plugin versions prior to 6.1.5
Description The issue is related to a SQL injection that occurs because a parameter is not properly sanitised and escaped before being used in a SQL statement. This can be exploited by administrators.
Recommendations For versions prior to 6.1.5, update to version 6.1.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's administrative interface to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-0365

Affected Products

Fancy Product Designer