CVE Published: 17/10/2024 |
CVE Updated: 17/10/2024 |
CVE Year: 2024 Source: Patchstack |
Vendor: WPGrim |
Product: Classic Editor and Classic Widgets Status : PUBLISHED
CVE-2024-47312 Description
Improper Neutralization of Special Elements used in an SQL Command (\'SQL Injection\') vulnerability in WPGrim Classic Editor and Classic Widgets allows SQL Injection.This issue affects Classic Editor and Classic Widgets: from n/a through 1.4.1.
Metrics
CVSS Version: 3.1 |
Base Score: 8.5 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L