First published: Wed Apr 24 2024(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall: from n/a through 16.26.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP-Recall | <=16.26.5 | |
WP-Recall | <=16.26.5 |
Update to 16.26.6 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-32709 is classified as a critical severity SQL injection vulnerability.
To mitigate CVE-2024-32709, update the WP-Recall plugin to a version beyond 16.26.5.
CVE-2024-32709 affects the WP-Recall plugin versions from n/a through 16.26.5.
CVE-2024-32709 is an SQL injection vulnerability caused by improper neutralization of special elements in SQL commands.
Yes, successful exploitation of CVE-2024-32709 could allow attackers to gain unauthorized access to database information.