CVE-2024-8855

CVE-2024-8855: WordPress Auction <= 3.7 - Editor+ SQL Injection

Vendor Unknown
Product WordPress Auction Plugin
Published January 7, 2025
Last update January 7, 2025

CVSS base score

What the vulnerability does

01Description

The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing editors and above to perform SQL injection attacks

Key dates

02Disclosure timeline

January 7, 2025 CVE published
January 7, 2025 Record updated