CVE-2024-37090: SQL Injection vulnerability in multiple StylemixThemes premium themes
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Masterstudy Elementor Widgets, StylemixThemes Consulting Elementor Widgets.This issue affects Masterstudy Elementor Widgets: from n/a through 1.2.2; Consulting Elementor Widgets: from n/a through 1.3.0.
Affected Software
Remediation
Information
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37090?
CVE-2024-37090 is classified as a critical SQL injection vulnerability.
How do I fix CVE-2024-37090?
To fix CVE-2024-37090, update the StylemixThemes Masterstudy Elementor Widgets to version 1.2.3 or later and the Consulting Elementor Widgets to version 1.3.1 or later.
What types of applications are affected by CVE-2024-37090?
CVE-2024-37090 affects the StylemixThemes Masterstudy Elementor Widgets and Consulting Elementor Widgets for WordPress.
What are the potential impacts of CVE-2024-37090?
Exploitation of CVE-2024-37090 can allow an attacker to execute arbitrary SQL commands on the database.
Are there any mitigations available for CVE-2024-37090?
The only effective mitigation for CVE-2024-37090 is to apply the necessary updates to the affected plugins.