The Advanced Search WordPress plugin through 1.1.6 does not properly escape parameters appended to an SQL query, making it possible for users with the administrator role to conduct SQL Injection attacks in the context of a multisite WordPress configurations.
History

Thu, 08 May 2025 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Advance Search Project
Advance Search Project advance Search
Weaknesses CWE-89
CPEs cpe:2.3:a:advance_search_project:advance_search:*:*:*:*:*:wordpress:*:*
Vendors & Products Advance Search Project
Advance Search Project advance Search

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-04-25T21:25:07.990Z

Updated: 2024-08-01T20:05:08.327Z

Reserved: 2024-04-03T14:22:48.163Z

Link: CVE-2024-3265

cve-icon Vulnrichment

Updated: 2024-08-01T20:05:08.327Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-25T22:15:09.043

Modified: 2025-05-08T19:14:12.707

Link: CVE-2024-3265

cve-icon Redhat

No data.