← back
CVE-2024-3265medium

WP Advanced Search <= 1.1.6 - Admin+ SQL Injection

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.7epss 0.4%
exploitation probability
0.4%top 66% of all CVEs
observed exploitation
nono source reports it
The Advanced Search WordPress plugin through 1.1.6 does not properly escape parameters appended to an SQL query, making it possible for users with the administrator role to conduct SQL Injection attacks in the context of a multisite WordPress configurations.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L