Sploitus

CVE-2024-9796

7 known exploits for CVE-2024-9796

The WP-Advanced-Search WordPress plugin before 3.3.9.2 does not sanitize and escape the t parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

Affected products
Wp-Advanced-Search
Internet-formation Wp-advanced-search
< 3.3.9.2
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
3.0% (87th percentile)
Weakness
CWE-89
NVD status
Analyzed
Published
2024-10-10
CVE-2024-9796 at NVD
Authoritative description, scoring and affected products

7 known exploits for CVE-2024-9796

Proof-of-concept code and exploit modules indexed by Sploitus