First published: Wed Apr 24 2024(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall: from n/a through 16.26.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP-Recall | <=16.26.5 | |
WP-Recall | <=16.26.5 |
Update to 16.26.6 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-32710 has a high severity rating due to its potential for SQL injection attacks.
To fix CVE-2024-32710, update the WP-Recall plugin to version 16.26.6 or later.
CVE-2024-32710 affects all versions of WP-Recall from its initial release up to and including version 16.26.5.
CVE-2024-32710 can allow attackers to execute arbitrary SQL commands, potentially compromising your database.
There are no effective workarounds for CVE-2024-32710; updating the plugin is recommended to mitigate the risk.