CVE-2024-6159: Push Notification for Post and BuddyPress <=1.93 - Multiple Unauthenticated SQLi
The Push Notification for Post and BuddyPress WordPress plugin before 1.9.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6159?
CVE-2024-6159 has been classified with a high severity level due to the potential for SQL injection vulnerabilities.
How do I fix CVE-2024-6159?
To fix CVE-2024-6159, update the Push Notification for Post and BuddyPress plugin to version 1.9.4 or later.
Who is affected by CVE-2024-6159?
CVE-2024-6159 affects users of the Push Notification for Post and BuddyPress WordPress plugin versions prior to 1.9.4.
What type of vulnerability is CVE-2024-6159?
CVE-2024-6159 is a SQL injection vulnerability caused by improper sanitization and escaping of parameters.
Can unauthenticated users exploit CVE-2024-6159?
Yes, CVE-2024-6159 can be exploited by unauthenticated users through an AJAX action.