WBW Product Table Pro <= 1.9.4 - Unauthenticated Arbitrary SQL Execution

2024-08-22 00:00
Dave Jong

Strategic Overview

Status
Patched in 1.9.5
Affected PluginWBW Product Table Pro
Affected Version<= 1.9.4
CVSS10.0Critical
CVECVE-2024-43918
View all WBW Product Table Pro vulnerabilities

Vulnerability Overview

The WBW Product Table Pro plugin for WordPress is vulnerable to unauthorized arbitrary SQL Execution due to a missing capability check on a function in all versions up to, and including, 1.9.4. This makes it possible for unauthenticated attackers to execute arbitrary SQL queries that can be used to steal sensitive data or gain elevated access to a vulnerable site.

Technical Analysis

REMEDIATION: Update to version 1.9.5, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C