First published: Fri Mar 29 2024(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.7.9.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP Travel Travel Engine | <5.8.0 | |
WP Travel Engine | <=5.7.9 |
Update to 5.8.0 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-30502 is categorized as a high severity SQL injection vulnerability.
To mitigate CVE-2024-30502, update WP Travel Engine to version 5.8.0 or later.
CVE-2024-30502 affects WP Travel Engine versions from n/a to 5.7.9.
Yes, CVE-2024-30502 is an unauthenticated SQL injection vulnerability.
Exploiting CVE-2024-30502 may allow attackers to execute arbitrary SQL queries on your database.