PT-2024-15770 · WordPress · Cryptocurrency Widgets – Price Ticker & Coins List

Thomas V

+1

·

Published

2024-01-20

·

Updated

2025-03-18

·

CVE-2024-0709

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cryptocurrency Widgets – Price Ticker & Coins List plugin for WordPress versions 2.0 through 2.6.5
Description The issue is related to SQL Injection via the coinslist parameter due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This allows unauthenticated attackers to append additional SQL queries into already existing queries, which can be used to extract sensitive information from the database.
Recommendations For versions 2.0 through 2.6.5, consider disabling the coinslist parameter until a patch is available to prevent SQL Injection attacks. Restrict access to the SQL query to minimize the risk of exploitation. Avoid using the coinslist parameter in the affected plugin until the issue is resolved.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-0709

Affected Products

Cryptocurrency Widgets – Price Ticker & Coins List