First published: Fri Dec 13 2024(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hive Support Hive Support – WordPress Help Desk allows SQL Injection.This issue affects Hive Support – WordPress Help Desk: from n/a through 1.1.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hive Support WordPress Help Desk | <=1.1.2 | |
WordPress Hive Support | <=1.1.2 |
Update the WordPress Hive Support – WordPress Help Desk plugin to the latest available version (at least 1.1.3).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-54304 has a high severity rating due to its SQL Injection vulnerability.
To fix CVE-2024-54304, update the Hive Support – WordPress Help Desk plugin to version 1.1.3 or later.
CVE-2024-54304 affects versions of Hive Support – WordPress Help Desk from n/a through 1.1.2.
An SQL Injection vulnerability like CVE-2024-54304 allows an attacker to manipulate SQL queries to access or alter the database.
As of now, there are no specific known exploits publicly available for CVE-2024-54304, but it remains critical to apply the patch immediately.