CVE-2024-43942: WordPress Greenshift Query and Meta Addon plugin < 3.9.2 - Subscriber+ SQL Injection vulnerability
Published Aug 29, 2024
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wpsoul Greenshift Query and Meta Addon allows SQL Injection.This issue affects Greenshift Query and Meta Addon: from n/a before 3.9.2.
Affected Software
1 affected component
Wpsoul Greenshift Query Addon Wordpress<3.9.2
Remediation
Information
Update to 3.9.2 or a higher version.
Event History
Aug 29, 2024
CVE Published
via MITRE·03:11 PM
Data Sourced
via MITRE·03:11 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-43942?
CVE-2024-43942 is classified as a critical SQL Injection vulnerability.
2
How do I fix CVE-2024-43942?
To fix CVE-2024-43942, update the Greenshift Query and Meta Addon to version 3.9.2 or later.
3
What systems are affected by CVE-2024-43942?
CVE-2024-43942 affects versions of the Greenshift Query and Meta Addon prior to 3.9.2.
4
What type of vulnerability is CVE-2024-43942?
CVE-2024-43942 involves improper neutralization of special elements used in an SQL command, allowing for SQL injection.
5
Can CVE-2024-43942 be exploited remotely?
Yes, CVE-2024-43942 can be exploited remotely by an attacker to execute arbitrary SQL commands.