CVE-2024-10499

HIGH

AI Engine WordPress Plugin < 2.6.5 - Authenticated SQL Injection via REST API Parameter

Title source: llm
STIX 2.1

Description

The AI Engine WordPress plugin before 2.6.5 does not sanitize and escape a parameter from one of its RESP API endpoint before using it in a SQL statement, allowing admins to perform SQL injection attacks

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/8606a93a-f61d-40df-a67e-0ac75eeadee8/

Scores

CVSS v3 7.2
EPSS 0.0058
EPSS Percentile 43.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
meowapps/ai_engine < 2.6.5
Published Dec 12, 2024
Tracked Since Feb 18, 2026