CVE-2024-27956
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0.
- Affected products
- Valvepress Automatic, Wordpress
- Valvepress Automatic
- ≤ 3.92.0
- Fix
- Available
- CVSS 3.1
- 9.9 CRITICAL
- EPSS
- 94.0% (100th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2024-03-21
- Attack patterns
- CAPEC-66
Fix
Update to 3.92.1 or a higher version.
CVE-2024-27956 at NVD
32 known exploits for CVE-2024-27956
Proof-of-concept code and exploit modules indexed by Sploitus
wordpress-CVE-2024-27956
CVE-2024-27956-WORDPRESS-RCE-PLUGIN
CVE-2024-27956
CVE-2024-27956-RCE-File-Package
CVE-2024-27956-RCE
Valve-Press-CVE-2024-27956-RCE
CVE-2024-27956-RCE
CVE-2024-27956
CVE-2024-27956
CVE-2024-27956
EXPLOITING-CVE-2024-27956
MASS-CVE-2024-27956
CVE-2024-27956-for-fscan
CVE-2024-27956
CVE-2024-27956
CVE-2024-27956
Exploit for SQL Injection in Valvepress Automatic
Exploit for SQL Injection in Valvepress Automatic
Exploit for SQL Injection in Valvepress Automatic
Exploit for SQL Injection in Valvepress Automatic
WordPress WP-Automatic SQL Injection Exploit
WordPress WP-Automatic SQL Injection
Exploit for SQL Injection in Valvepress Automatic
Exploit for SQL Injection in Valvepress Automatic
Exploit for SQL Injection in Valvepress Automatic
Exploit for SQL Injection in Valvepress Automatic
Exploit for SQL Injection in Valvepress Automatic
Exploit for SQL Injection in Valvepress Automatic
Exploit for SQL Injection in Valvepress Automatic
Exploit for SQL Injection in Valvepress Automatic
Exploit for SQL Injection in Valvepress Automatic
WordPress wp-automatic Plugin SQLi Admin Creation