CVE-2024-8855: WordPress Auction <= 3.7 - Editor+ SQL Injection
Published Jan 7, 2025
·Updated
The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing editors and above to perform SQL injection attacks
Affected Software
2 affected components
WordPress Auction Plugin<=3.7
Wpmarka Wordpress Auction Wordpress<=3.7
Event History
Jan 7, 2025
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-8855?
CVE-2024-8855 is considered a high severity vulnerability due to its potential for SQL injection attacks.
2
How do I fix CVE-2024-8855?
To fix CVE-2024-8855, update the WordPress Auction Plugin to version 3.8 or later where the vulnerability has been addressed.
3
Who is affected by CVE-2024-8855?
The vulnerability CVE-2024-8855 affects users of the WordPress Auction Plugin version 3.7 and below.
4
What type of attack can be performed using CVE-2024-8855?
CVE-2024-8855 allows attackers to perform SQL injection attacks, possibly compromising the database.
5
What versions of the WordPress Auction Plugin are vulnerable to CVE-2024-8855?
Versions of the WordPress Auction Plugin up to and including 3.7 are vulnerable to CVE-2024-8855.