WordPress Plugin Alert – Critical SQLi Vulnerability Threatens 200K+ Websites

With over 200,000 active installs, the well-known WordPress plugin Ultimate Member has a serious security problem that has come to light.

With a maximum score of 10, the vulnerability, identified as CVE-2024-1071, has a CVSS score of 9.8. It is acknowledged that security researcher Christiaan Swiers found and reported the vulnerability.

Wordfence, a WordPress security company, stated in a warning released last week that the plugin is susceptible to SQL Injection via the’sorting’ parameter in versions 2.1.3 to 2.8.2 because there is inadequate escaping on the user-supplied parameter and inadequate preparation on the current SQL query.

Therefore, the vulnerability might be used by unauthenticated attackers to append more SQL queries to already existing read more WordPress Plugin Alert Critical SQLi Vulnerability Threatens 200K Websites.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *