CVE-2024-43918: WordPress WBW Product Table PRO plugin <= 1.9.4 - Unauthenticated Arbitrary SQL Query Execution vulnerability
Published Aug 29, 2024
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW WBW Product Table PRO allows SQL Injection.This issue affects WBW Product Table PRO: from n/a through 1.9.4.
Affected Software
1 affected component
Woobewoo Product Table Wordpress<1.9.5
Remediation
Information
Update to 1.9.5 or a higher version.
Event History
Aug 29, 2024
CVE Published
via MITRE·02:49 PM
Data Sourced
via MITRE·02:49 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-43918?
CVE-2024-43918 is classified as a high severity SQL Injection vulnerability.
2
How do I fix CVE-2024-43918?
To fix CVE-2024-43918, upgrade the WBW Product Table PRO to version 1.9.5 or later.
3
What type of vulnerability is CVE-2024-43918?
CVE-2024-43918 is an SQL Injection vulnerability that allows attackers to execute arbitrary SQL commands.
4
Which software versions are affected by CVE-2024-43918?
CVE-2024-43918 affects WBW Product Table PRO versions up to 1.9.4.
5
Is user authentication required to exploit CVE-2024-43918?
No, CVE-2024-43918 can be exploited without user authentication.