CVE Published: 13/09/2024 |
CVE Updated: 13/09/2024 |
CVE Year: 2024 Source: WPScan |
Vendor: Unknown |
Product: AI Engine Status : PUBLISHED
CVE-2024-6723 Description
The AI Engine WordPress plugin before 2.4.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when viewing chatbot discussions.