momo安全漏洞库

多模块数据检索平台

登录 注册
返回列表

CVE-2024-12025: WordPress Collapsing Categories <= 3.0.8 - SQL Injection

CVE: CVE-2024-12025
CNVD: 暂无
CNNVD: 暂无
漏洞类型: SQL注入
漏洞等级: 高危
年份: 2026
POC_ID: 暂无
漏洞描述
Collapsing Categories plugin for WordPress <= 3.0.8 contains a sql_injection caused by insufficient escaping of 'taxonomy' parameter in /wp-json/collapsing-categories/v1/get REST API, letting unauthenticated attackers execute arbitrary SQL queries, exploit requires sending crafted 'taxonomy' parameter. [已公开] id: CVE-2024-12025 info: name: WordPress Collapsing Categories <= 3.0.8 - SQL Injection author: Shivam Kamboj severity: high description: | Collapsing Categories plugin for WordPress <= 3.0.8 contains a sql_injection caused by insufficient escaping of 'taxonomy' parameter in /wp-json/collapsing-categories/v1/get REST API, letting unauthenticated attackers execute arbitrary SQL queries, exploit requires sending crafted 'taxonomy' parameter. impact: | Attackers can execute arbitrary SQL queries, potentially leading to data leakage or database compromise. remediation: | Update to the latest version of the plugin that addresses this vulnerability or apply security patches provided by the vendor. reference: - https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/collapsing-categories/collapsing-categories-308-unauthenticated-sql-injection - https://nvd.nist.gov/vu
FOFA 语句
暂无
影响范围
WordPress Collapsing Categories
漏洞详情
POC: 已公开
漏洞 POC
登录后可查看漏洞 POC。请先 登录注册
修复建议
暂无