CVE Database
/

CVE-2024-9156

Back to search

CVE-2024-9156

Published: Oct 10, 2024

Modified: Oct 10, 2024

PUBLISHED

Description

The TI WooCommerce Wishlist WordPress plugin through 2.8.2 is vulnerable to SQL Injection due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

VendorProductVersions

Unknown

TI WooCommerce Wishlist

affected
0 - <= 2.8.2

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now