The Advanced Search WordPress plugin through 1.1.6 does not properly escape parameters appended to an SQL query, making it possible for users with the administrator role to conduct SQL Injection attacks in the context of a multisite WordPress configurations.
Metrics
Affected Vendors & Products
References
History
Thu, 08 May 2025 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Advance Search Project
Advance Search Project advance Search |
|
Weaknesses | CWE-89 | |
CPEs | cpe:2.3:a:advance_search_project:advance_search:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Advance Search Project
Advance Search Project advance Search |

Status: PUBLISHED
Assigner: WPScan
Published: 2024-04-25T21:25:07.990Z
Updated: 2024-08-01T20:05:08.327Z
Reserved: 2024-04-03T14:22:48.163Z
Link: CVE-2024-3265

Updated: 2024-08-01T20:05:08.327Z

Status : Analyzed
Published: 2024-04-25T22:15:09.043
Modified: 2025-05-08T19:14:12.707
Link: CVE-2024-3265

No data.