← back
CVE-2024-9186high

Automation By Autonami < 3.3.0 - Unauthenticated SQLi

36Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 8.6epss 2.3%
exploitation probability
2.3%top 19% of all CVEs
observed exploitation
nono source reports it
The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit WordPress plugin before 3.3.0 does not sanitize and escape the bwfan-track-id parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N