First published: Mon Dec 16 2024(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design WPBookit allows SQL Injection.This issue affects WPBookit: from n/a through 1.6.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WPBookit | <=1.6.0 | |
WPBookit | <=1.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-54280 is classified as a high-severity SQL Injection vulnerability.
To remediate CVE-2024-54280, update the WPBookit plugin to a version newer than 1.6.0.
CVE-2024-54280 is an SQL Injection vulnerability in the Iqonic Design WPBookit plugin, affecting versions up to 1.6.0.
Users of the Iqonic Design WPBookit plugin from version 1.6.0 and earlier are affected by CVE-2024-54280.
Attackers can exploit CVE-2024-54280 to execute arbitrary SQL commands on the database.