CVE-2024-12773: Altra Side Menu <= 2.0 - Admin+ SQL Injection
Published Jan 27, 2025
·Updated
The Altra Side Menu WordPress plugin through 2.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
Affected Software
2 affected components
Pulseextensions Altra Side Menu Wordpress<=2.0
Altra Side Menu<=2.0
Event History
Jan 27, 2025
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-12773?
The severity of CVE-2024-12773 is considered high due to its potential for SQL injection attacks that can compromise the database.
2
How do I fix CVE-2024-12773?
To fix CVE-2024-12773, update the Altra Side Menu plugin to a version above 2.0 where the SQL injection vulnerability is patched.
3
Who is affected by CVE-2024-12773?
CVE-2024-12773 affects users of the Altra Side Menu WordPress plugin version 2.0 and below.
4
What type of attack can be performed using CVE-2024-12773?
An attacker can exploit CVE-2024-12773 to conduct SQL injection attacks against the vulnerable WordPress site.
5
Is CVE-2024-12773 an urgent vulnerability to address?
Yes, CVE-2024-12773 is urgent to address as it allows potential database compromise through SQL injection.