CVE-2024-27956: critical vulnerability in ValvePress Automatic
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
Published · Updated
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
The WordPress Automatic plugin allows attackers to execute arbitrary SQL commands without needing to log in, potentially exposing or modifying sensitive database information. This happens because the plugin does not properly validate user input before using it in database queries.
CWE-89 SQL Injection vulnerability in Automatic plugin versions up to 3.92.0 allows unauthenticated attackers to inject malicious SQL commands through inadequately sanitized input parameters. Successful exploitation enables unauthorized database access, data exfiltration, or modification without requiring valid credentials.
In the same product, most dangerous first.