CVE-2024-9186: Automation By Autonami < 3.3.0 - Unauthenticated SQLi
Published Nov 14, 2024
·Updated
The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit WordPress plugin before 3.3.0 does not sanitize and escape the bwfan-track-id parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks
Affected Software
2 affected components
FunnelKit Funnelkit Automations Wordpress<3.3.0
FunnelKit FunnelKit WordPress plugin<3.3.0
Event History
Nov 14, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverity
Apr 28, 56937
Event
via FIRST·03:47 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-9186?
CVE-2024-9186 is classified as a critical vulnerability due to the potential for SQL injection.
2
How do I fix CVE-2024-9186?
To fix CVE-2024-9186, update the FunnelKit WordPress plugin to version 3.3.0 or later.
3
What kind of attack does CVE-2024-9186 allow?
CVE-2024-9186 allows unauthenticated users to perform SQL injection attacks.
4
Which versions of the FunnelKit WordPress plugin are affected by CVE-2024-9186?
CVE-2024-9186 affects all versions of the FunnelKit WordPress plugin before 3.3.0.
5
Is user authentication required to exploit CVE-2024-9186?
No, user authentication is not required to exploit CVE-2024-9186.