PT-2025-1797 · WordPress · Safe Ai Malware Protection For Wp

Tieu Pham Trong Nhan

·

Published

2025-01-30

·

Updated

2025-01-31

·

CVE-2024-12269

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Safe Ai Malware Protection for WP plugin for WordPress versions up to, and including, 1.0.17
Description The issue is related to unauthorized access of data due to a missing capability check on the export db() function. This allows unauthenticated attackers to retrieve a complete dump of the site's database.
Recommendations For versions up to, and including, 1.0.17, update to a version higher than 1.0.17 to resolve the issue. As a temporary workaround, consider disabling the export db() function until a patch is available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-12269

Affected Products

Safe Ai Malware Protection For Wp