CVE-2024-47304: WordPress Fluent Support plugin <= 1.8.0 - SQL Injection vulnerability
Published Oct 17, 2024
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Fluent Support fluent-support allows SQL Injection.This issue affects Fluent Support: from n/a through <= 1.8.0.
Affected Software
3 affected components
WPManageNinja Fluent Support<=1.8.0
WordPress Fluent Support<=1.8.0
WPManageNinja Fluent Support Wordpress<1.8.1
Remediation
Information
Update to 1.8.1 or a higher version.
Event History
Oct 17, 2024
CVE Published
via MITRE·05:36 PM
Data Sourced
via MITRE·05:36 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-47304?
CVE-2024-47304 is classified as a high-severity SQL Injection vulnerability.
2
How do I fix CVE-2024-47304?
To fix CVE-2024-47304, upgrade Fluent Support to version 1.8.1 or later.
3
What is the impact of CVE-2024-47304?
The impact of CVE-2024-47304 includes potential unauthorized access to sensitive data and manipulation of the database.
4
Which versions are affected by CVE-2024-47304?
CVE-2024-47304 affects all Fluent Support versions up to and including 1.8.0.
5
Who is the vendor associated with CVE-2024-47304?
The vendor associated with CVE-2024-47304 is WPManageNinja LLC.