CVE-2024-47325: WordPress Multiple Page Generator Plugin – MPG plugin <= 3.4.7 - SQL Injection vulnerability
Published Oct 20, 2024
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle MPG multiple-pages-generator-by-porthas allows SQL Injection.This issue affects MPG: from n/a through <= 3.4.7.
Affected Software
1 affected component
Themeisle Multiple Page Generator Wordpress<3.4.8
Remediation
Information
Update to 3.4.8 or a higher version.
Event History
Oct 20, 2024
CVE Published
via MITRE·10:03 AM
Data Sourced
via MITRE·10:03 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-47325?
CVE-2024-47325 is a high severity vulnerability due to its potential to allow SQL Injection.
2
How do I fix CVE-2024-47325?
To fix CVE-2024-47325, update the Multiple Page Generator Plugin – MPG to version 3.4.8 or later.
3
What software is affected by CVE-2024-47325?
CVE-2024-47325 affects the Multiple Page Generator Plugin – MPG versions from n/a through 3.4.7.
4
What type of vulnerability is CVE-2024-47325?
CVE-2024-47325 is categorized as an SQL Injection vulnerability.
5
Can CVE-2024-47325 be exploited remotely?
Yes, CVE-2024-47325 can potentially be exploited remotely if the vulnerable plugin is used in a web application.