The Opti Marketing WordPress plugin through 2.0.9 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

Project Subscriptions

Vendors Products
Opti.marketing Subscribe
Opti Marketing Subscribe
Optimarketing Subscribe
Opti Marketing Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 07 Oct 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Opti.marketing
Opti.marketing opti Marketing
Weaknesses CWE-89
CPEs cpe:2.3:a:opti.marketing:opti_marketing:*:*:*:*:*:wordpress:*:*
Vendors & Products Opti.marketing
Opti.marketing opti Marketing

Tue, 10 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Optimarketing
Optimarketing opti Marketing
CPEs cpe:2.3:a:optimarketing:opti_marketing:*:*:*:*:*:*:*:*
Vendors & Products Optimarketing
Optimarketing opti Marketing
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 08 Sep 2024 06:15:00 +0000

Type Values Removed Values Added
Description The Opti Marketing WordPress plugin through 2.0.9 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
Title Opti Marketing <= 2.0.9 - Unauthenticated SQLi
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-09-10T14:11:39.495Z

Reserved: 2024-07-19T19:57:53.919Z

Link: CVE-2024-6928

cve-icon Vulnrichment

Updated: 2024-09-10T14:11:34.205Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-08T06:15:02.747

Modified: 2024-10-07T17:45:47.083

Link: CVE-2024-6928

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses