WBW Product Table Pro <= 1.9.4 - Unauthenticated Arbitrary SQL Execution
2024-08-22 00:00
Dave JongStrategic Overview
StatusPatched in 1.9.5
Affected PluginWBW Product Table Pro
Affected Version
<= 1.9.4CVSS10.0Critical
CVE
CVE-2024-43918Vulnerability Overview
The WBW Product Table Pro plugin for WordPress is vulnerable to unauthorized arbitrary SQL Execution due to a missing capability check on a function in all versions up to, and including, 1.9.4. This makes it possible for unauthenticated attackers to execute arbitrary SQL queries that can be used to steal sensitive data or gain elevated access to a vulnerable site.
Technical Analysis
REMEDIATION: Update to version 1.9.5, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C