CVE-2024-3265: WP Advanced Search <= 1.1.6 - Admin+ SQL Injection
The Advanced Search WordPress plugin through 1.1.6 does not properly escape parameters appended to an SQL query, making it possible for users with the administrator role to conduct SQL Injection attacks in the context of a multisite WordPress configurations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3265?
CVE-2024-3265 is considered a high severity vulnerability due to its potential for SQL Injection attacks.
Who is affected by CVE-2024-3265?
Only users with the administrator role in multisite WordPress configurations are affected by CVE-2024-3265.
How do I fix CVE-2024-3265?
To fix CVE-2024-3265, update the Advanced Search WordPress plugin to version 1.1.7 or later.
What type of attack does CVE-2024-3265 enable?
CVE-2024-3265 enables SQL Injection attacks by improperly escaping parameters in SQL queries.
Which versions of the Advanced Search plugin are affected by CVE-2024-3265?
CVE-2024-3265 affects versions of the Advanced Search WordPress plugin up to and including 1.1.6.