CVE-2024-32128: WordPress Realtyna Organic IDX plugin + WPL Real Estate plugin <= 4.14.4 - Unauthenticated SQL Injection vulnerability
Published Apr 15, 2024
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Realtyna Realtyna Organic IDX plugin.This issue affects Realtyna Organic IDX plugin: from n/a through 4.14.4.
Affected Software
2 affected components
Realtyna Realtyna Organic IDX plugin<=4.14.4
Realtyna WPL Real Estate plugin<=4.14.4
Event History
Apr 15, 2024
CVE Published
via MITRE·07:35 AM
Data Sourced
via MITRE·07:35 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-32128?
CVE-2024-32128 is rated as a critical vulnerability due to its potential for SQL Injection exploitation.
2
How do I fix CVE-2024-32128?
To fix CVE-2024-32128, update the Realtyna Organic IDX plugin to version 4.14.5 or later.
3
Which versions of Realtyna Organic IDX are affected by CVE-2024-32128?
CVE-2024-32128 affects the Realtyna Organic IDX plugin versions from n/a up to and including 4.14.4.
4
What type of vulnerability is CVE-2024-32128?
CVE-2024-32128 is an SQL Injection vulnerability that allows attackers to execute arbitrary SQL commands in the database.
5
Is authentication required to exploit CVE-2024-32128?
No, CVE-2024-32128 is an unauthenticated SQL Injection vulnerability, meaning it can be exploited without user credentials.