CVE-2024-30502: WordPress WP Travel Engine plugin <= 5.7.9 - Unauth. Blind SQL Injection vulnerability
Published Mar 29, 2024
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.7.9.
Affected Software
2 affected components
Wptravelengine Wp Travel Engine Wordpress<5.8.0
WP Travel WP Travel Engine<=5.7.9
Remediation
Information
Update to 5.8.0 or a higher version.
Event History
Mar 29, 2024
CVE Published
via MITRE·02:08 PM
Data Sourced
via MITRE·02:08 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Sep 4, 57087
Event
via NVD·02:38 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-30502?
CVE-2024-30502 is categorized as a high severity SQL injection vulnerability.
2
How do I fix CVE-2024-30502?
To mitigate CVE-2024-30502, update WP Travel Engine to version 5.8.0 or later.
3
Which versions of WP Travel Engine are affected by CVE-2024-30502?
CVE-2024-30502 affects WP Travel Engine versions from n/a to 5.7.9.
4
Is CVE-2024-30502 exploitable without authentication?
Yes, CVE-2024-30502 is an unauthenticated SQL injection vulnerability.
5
What impact does CVE-2024-30502 have on my website?
Exploiting CVE-2024-30502 may allow attackers to execute arbitrary SQL queries on your database.