CVE-2024-27956
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
In short
The WordPress Automatic plugin allows attackers to execute arbitrary SQL commands without needing to log in, potentially exposing or modifying sensitive database information. This happens because the plugin does not properly validate user input before using it in database queries.
Technical detail
CWE-89 SQL Injection vulnerability in Automatic plugin versions up to 3.92.0 allows unauthenticated attackers to inject malicious SQL commands through inadequately sanitized input parameters. Successful exploitation enables unauthorized database access, data exfiltration, or modification without requiring valid credentials.
Summary generated and translated by AI from the official description.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L
Affected products
ValvePress · Automaticpublic PoCs found — 16
githubgithub.com/diego-tella/CVE-2024-27956-RCE★ 90githubgithub.com/Ap0dexMe0/CVE-2024-27956★ 8githubgithub.com/itzheartzz/MASS-CVE-2024-27956★ 3githubgithub.com/Cappricio-Securities/CVE-2024-27956★ 2githubgithub.com/truonghuuphuc/CVE-2024-27956★ 2githubgithub.com/FoxyProxys/CVE-2024-27956★ 1githubgithub.com/devsec23/CVE-2024-27956★ 1githubgithub.com/7aRanchi/CVE-2024-27956-for-fscan★ 0githubgithub.com/m4nInTh3mIdDle/wordpress-CVE-2024-27956★ 0githubgithub.com/0axz-tools/CVE-2024-27956★ 0githubgithub.com/X-Projetion/CVE-2024-27956-WORDPRESS-RCE-PLUGIN★ 0githubgithub.com/k3ppf0r/CVE-2024-27956★ 0githubgithub.com/W3BW/CVE-2024-27956-RCE-File-Package★ 0githubgithub.com/hitazuranahiro/Valve-Press-CVE-2024-27956-RCE★ 0githubgithub.com/cve-2024/CVE-2024-27956-RCE★ 0githubgithub.com/CERTologists/EXPLOITING-CVE-2024-27956★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →