CVE-2024-30237 HIGH

CVE-2024-30237: WordPress Slider by Supsystic plugin <= 1.8.10 - SQL Injection vulnerability

Vendor Supsystic
Product Slider by Supsystic
Weakness CWE-89 · SQLi
Published March 28, 2024
Last update April 28, 2026

CVSS base score

7.6/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

What the vulnerability does

01Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Supsystic Slider by Supsystic.This issue affects Slider by Supsystic: from n/a through 1.8.10.

Explanation of Vulnerability in Simple Terms

02Summary

Slider by Supsystic versions up to 1.8.10 contain a SQL injection vulnerability accessible to high-privilege users. An attacker with admin or editor access can craft malicious input to extract or modify database contents. The vulnerability requires administrative credentials and does not affect data integrity, but can expose sensitive information and degrade site performance.

What an attacker can do

03Attacker Capabilities

Read sensitive data from the site database, such as user credentials or configuration details.

Potential impact on your site

04Site Impact

A compromised admin account could expose your database contents or cause service disruption.

Conditions required to exploit

05Prerequisites

Attacker must have high-level site access (admin or editor role); no user interaction required.

Key dates

06Disclosure timeline

March 28, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE