CVE-2024-6205: PayPlus Payment Gateway < 6.6.9 - Unauthenticated SQLi
The PayPlus Payment Gateway WordPress plugin before 6.6.9 does not properly sanitise and escape a parameter before using it in a SQL statement via a WooCommerce API route available to unauthenticated users, leading to an SQL injection vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6205?
CVE-2024-6205 is classified as a high severity vulnerability due to its potential for allowing SQL injection attacks.
How do I fix CVE-2024-6205?
To fix CVE-2024-6205, update the PayPlus Payment Gateway plugin to version 6.6.9 or later.
What types of attacks can CVE-2024-6205 facilitate?
CVE-2024-6205 can facilitate SQL injection attacks that may lead to unauthorized access to the database.
Who is affected by CVE-2024-6205?
CVE-2024-6205 affects users of the PayPlus Payment Gateway WordPress plugin version prior to 6.6.9.
Is CVE-2024-6205 applicable to authenticated users?
CVE-2024-6205 is particularly concerning because it allows unauthenticated users to exploit the vulnerability via WooCommerce API routes.