Vulnerability Description
The Search & Replace WordPress plugin before 3.2.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks (such as within a multi-site network).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wp-Media | Search \& Replace | < 3.2.2 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/7d5b8764-c82d-4969-a707-f38b63bcadca/ExploitThird Party Advisory
- https://wpscan.com/vulnerability/7d5b8764-c82d-4969-a707-f38b63bcadca/ExploitThird Party Advisory
FAQ
What is CVE-2024-4145?
CVE-2024-4145 is a vulnerability with a CVSS score of 7.2 (HIGH). The Search & Replace WordPress plugin before 3.2.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks (such as within a multi...
How severe is CVE-2024-4145?
CVE-2024-4145 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-4145?
Check the references section above for vendor advisories and patch information. Affected products include: Wp-Media Search \& Replace.