CVE-2024-52435: WordPress Premium Packages – Sell Digital Products Securely plugin <= 6.0.5 - SQL Injection vulnerability
Published Nov 18, 2024
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjada WPDM – Premium Packages wpdm-premium-packages.This issue affects WPDM – Premium Packages: from n/a through <= 6.0.5.
Affected Software
1 affected component
Wpdownloadmanager Premium Packages - Sell Digital Products Securely Wordpress<=5.9.3
Event History
Nov 18, 2024
CVE Published
via MITRE·02:36 PM
Data Sourced
via MITRE·02:36 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-52435?
CVE-2024-52435 is classified as an SQL Injection vulnerability which can lead to serious data breaches.
2
How do I fix CVE-2024-52435?
To fix CVE-2024-52435, update the Premium Packages plugin to version 5.9.4 or later.
3
What versions of Premium Packages are affected by CVE-2024-52435?
CVE-2024-52435 affects Premium Packages versions from n/a up to 5.9.3.
4
Can CVE-2024-52435 lead to data exposure?
Yes, CVE-2024-52435 can result in unauthorized access and data exposure through SQL Injection.
5
Is it safe to use Premium Packages if I have not updated for CVE-2024-52435?
No, using outdated versions vulnerable to CVE-2024-52435 poses security risks and should be avoided.