CVE Database /
CVE-2024-43917
CVE · Critical
CVE-2024-43917 — TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.9.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-43917
|
TI WooCommerce Wishlist [ti-woocommerce-wishlist] < 2.9.0 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
Critical
9.8
|
< 2.9.0
|
2.9.0 |
2024-08-22 |
—
|
CVE-2024-43917
The TI WooCommerce Wishlist plugin for WordPress has a vulnerability that allows attackers to inject malicious SQL code into the plugin's database queries. This is due to inadequate protection of user input, which can be exploited to extract sensitive information from the database. The vulnerability affects all versions up to and including 2.8.2, making it possible for unauthenticated attackers to access sensitive data.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings