CVE-2024-37494: WordPress Youzify plugin <= 1.2.5 - SQL Injection vulnerability
Published Jul 9, 2024
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in KaineLabs Youzify.This issue affects Youzify: from n/a through 1.2.5.
Affected Software
1 affected component
KaineLabs Youzify Wordpress<1.2.6
Remediation
Information
Update to 1.2.6 or a higher version.
Event History
Jul 9, 2024
CVE Published
via MITRE·08:59 AM
Data Sourced
via MITRE·08:59 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-37494?
CVE-2024-37494 is classified as a critical severity vulnerability due to its potential for SQL injection attacks.
2
How do I fix CVE-2024-37494?
To fix CVE-2024-37494, users should upgrade the Youzify plugin to version 1.2.6 or later.
3
What versions of Youzify are affected by CVE-2024-37494?
CVE-2024-37494 affects Youzify versions from n/a up to 1.2.5.
4
What types of attacks can CVE-2024-37494 allow?
CVE-2024-37494 can allow attackers to manipulate SQL queries, potentially leading to unauthorized data access.
5
Is CVE-2024-37494 specific to any platform?
Yes, CVE-2024-37494 specifically affects the Youzify plugin on the WordPress platform.