CVE-2024-8625: TS Poll – Survey, Versus Poll, Image Poll, Video Poll < 2.4.0 - Admin+ SQL Injection
Published Oct 21, 2024
·Updated
The TS Poll WordPress plugin before 2.4.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
Affected Software
1 affected component
Total-Soft Ts Poll Wordpress<2.4.0
Event History
Oct 21, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-8625?
CVE-2024-8625 has a high severity due to its potential for SQL injection attacks.
2
How do I fix CVE-2024-8625?
To fix CVE-2024-8625, update the TS Poll WordPress plugin to version 2.4.0 or later.
3
What type of attack does CVE-2024-8625 allow?
CVE-2024-8625 allows for SQL injection attacks due to inadequate parameter sanitization.
4
Who is affected by CVE-2024-8625?
CVE-2024-8625 affects users of the TS Poll WordPress plugin versions prior to 2.4.0.
5
What versions of TS Poll are vulnerable to CVE-2024-8625?
TS Poll WordPress plugin versions before 2.4.0 are vulnerable to CVE-2024-8625.