CVE-2024-37486: WordPress Paid Memberships Pro plugin <= 3.0.5 - Authenticated SQL Injection vulnerability
Published Jul 9, 2024
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 3.0.5.
Affected Software
1 affected component
Strangerstudios Paid Memberships Pro Wordpress<3.0.6
Remediation
Information
Update to 3.0.6 or a higher version.
Event History
Jul 9, 2024
CVE Published
via MITRE·09:01 AM
Data Sourced
via MITRE·09:01 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-37486?
CVE-2024-37486 is considered a high-severity vulnerability due to its potential for SQL injection exploitation.
2
How do I fix CVE-2024-37486?
To fix CVE-2024-37486, upgrade Paid Memberships Pro to version 3.0.6 or later.
3
What versions of Paid Memberships Pro are affected by CVE-2024-37486?
CVE-2024-37486 affects Paid Memberships Pro versions prior to 3.0.6.
4
What type of vulnerability is CVE-2024-37486?
CVE-2024-37486 is classified as an SQL injection vulnerability due to improper neutralization of special elements in SQL commands.
5
Can CVE-2024-37486 be exploited remotely?
Yes, CVE-2024-37486 can be exploited remotely if attacker has access to the vulnerable component.