CVE-2024-43132: WordPress Docket (WooCommerce Collections / Wishlist / Watchlist) plugin < 1.7.0 - Unauthenticated SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPWeb Elite Docket (WooCommerce Collections / Wishlist / Watchlist) allows SQL Injection.This issue affects Docket (WooCommerce Collections / Wishlist / Watchlist): from n/a before 1.7.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43132?
CVE-2024-43132 is classified as a high severity vulnerability due to its potential for SQL Injection.
How do I fix CVE-2024-43132?
To fix CVE-2024-43132, update the WPWeb Elite Docket plugin to version 1.7.0 or later.
What software is affected by CVE-2024-43132?
CVE-2024-43132 affects the WPWeb Elite Docket plugin for WordPress, specifically versions before 1.7.0.
What type of vulnerability is CVE-2024-43132?
CVE-2024-43132 is an SQL Injection vulnerability that results from improper neutralization of special elements in SQL commands.
Can CVE-2024-43132 be exploited without authentication?
Yes, CVE-2024-43132 can be exploited without authentication, making it even more critical to address.