First published: Fri Feb 23 2024(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sitepact.This issue affects Sitepact: from n/a through 1.0.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sitepact Contact Form 7 Extension For Klaviyo | <3.0.0 | |
Sitepact | <=1.0.5 | |
WordPress Extensions For CF7 | <=1.0.5 |
Update to 3.0.0 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25928 has high severity due to the potential for SQL Injection attacks.
To fix CVE-2024-25928, upgrade Sitepact or the WordPress Contact Form 7 Extension For Klaviyo Plugin to version 1.0.6 or later.
CVE-2024-25928 affects Sitepact versions up to and including 1.0.5.
CVE-2024-25928 is an SQL Injection vulnerability allowing attackers to manipulate database queries.
Users of Sitepact and the Contact Form 7 Extension For Klaviyo Plugin with affected versions are at risk.