CVE-2024-0365: Fancy Product Designer < 6.1.5 - Admin+ SQL Injection
Published Mar 18, 2024
·Updated
The Fancy Product Designer WordPress plugin before 6.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by adminstrators.
Affected Software
2 affected components
Fancy Product Designer WordPress Plugin<6.1.5
Radykal Fancy Product Designer Wordpress<6.1.5
Event History
Mar 18, 2024
CVE Published
via MITRE·07:05 PM
Data Sourced
via MITRE·07:05 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-0365?
CVE-2024-0365 has a high severity rating due to the potential for SQL injection attacks.
2
How do I fix CVE-2024-0365?
To fix CVE-2024-0365, update the Fancy Product Designer WordPress plugin to version 6.1.5 or later.
3
Who is affected by CVE-2024-0365?
Administrators using the Fancy Product Designer WordPress plugin versions before 6.1.5 are affected by CVE-2024-0365.
4
What are the consequences of exploiting CVE-2024-0365?
Exploiting CVE-2024-0365 can allow attackers to execute arbitrary SQL queries in the database.
5
Is CVE-2024-0365 related to WordPress security?
Yes, CVE-2024-0365 is specifically a vulnerability in the Fancy Product Designer WordPress plugin affecting its database security.