CVE-2024-47338: WordPress WPExperts Square For GiveWP plugin <= 1.3 - SQL Injection vulnerability
Published Oct 6, 2024
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal WPExperts Square For GiveWP wpexperts-square-for-give allows SQL Injection.This issue affects WPExperts Square For GiveWP: from n/a through <= 1.3.
Affected Software
1 affected component
Wpexperts WPExperts Square For GiveWP<=1.3
Event History
Oct 6, 2024
CVE Published
via MITRE·12:58 PM
Data Sourced
via MITRE·12:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionWeakness
Jul 19, 58279
Event
via MITRE·02:05 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-47338?
CVE-2024-47338 is classified as a critical SQL Injection vulnerability.
2
How do I fix CVE-2024-47338?
To fix CVE-2024-47338, upgrade WPExperts Square For GiveWP to a version above 1.3, where the vulnerability has been patched.
3
What software is affected by CVE-2024-47338?
CVE-2024-47338 affects WPExperts Square For GiveWP versions up to and including 1.3.
4
What type of vulnerability is CVE-2024-47338?
CVE-2024-47338 is an SQL Injection vulnerability due to improper neutralization of special elements used in an SQL command.
5
Who is the vendor of the affected product in CVE-2024-47338?
The vendor of the affected product in CVE-2024-47338 is WPExpertsio.