PT-2024-33444 · Wpfactory · Wpfactory Email Verification For Woocommerce

Shaman0X01

·

Published

2024-10-17

·

Updated

2024-10-18

·

CVE-2024-49305

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions WPFactory Email Verification for WooCommerce versions n/a through 2.8.10
Description The issue is related to an SQL Injection vulnerability, specifically an Improper Neutralization of Special Elements used in an SQL Command. This allows attackers to manipulate SQL queries.
Recommendations For versions n/a through 2.8.10, update to a version later than 2.8.10 to resolve the issue. As a temporary workaround, consider restricting access to sensitive database queries until a patch is available. Avoid using user-input data directly in SQL commands to minimize the risk of exploitation.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-49305

Affected Products

Wpfactory Email Verification For Woocommerce