CVE-2024-30504: WordPress WP Travel Engine plugin <= 5.7.9 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.7.9.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30504?
CVE-2024-30504 is classified as a high severity vulnerability due to its potential to allow an attacker to execute arbitrary SQL commands.
How do I fix CVE-2024-30504?
To address CVE-2024-30504, update WP Travel Engine to version 5.8.0 or later, which includes a patch for the SQL injection vulnerability.
Which versions of WP Travel Engine are affected by CVE-2024-30504?
CVE-2024-30504 affects all versions of WP Travel Engine from n/a up to and including 5.7.9.
What type of vulnerability is represented by CVE-2024-30504?
CVE-2024-30504 represents an SQL Injection vulnerability due to improper neutralization of special elements in SQL commands.
Is there a known exploit for CVE-2024-30504?
While specific exploits may not be publicly documented, the nature of SQL injection vulnerabilities commonly allows attackers to manipulate database queries.