CVE-2024-3265

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
25/04/2024
Last modified:
08/05/2025

Description

The Advanced Search WordPress plugin through 1.1.6 does not properly escape parameters appended to an SQL query, making it possible for users with the administrator role to conduct SQL Injection attacks in the context of a multisite WordPress configurations.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:advance_search_project:advance_search:*:*:*:*:*:wordpress:*:* 1.1.6 (including)