Record summary

CVE-2024-13726 has a selected CVSS score of 8.6 (high); EIP currently links 1 Nuclei template.

Description

The Coder WordPress plugin through 1.3.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 19, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Themes Coder

Default status: affected

CVE ListThrough 1.3.4affected

Nuclei templates

1
ProjectDiscoveryHIGHThemes Coder Ecommerce <= 1.3.4 - SQL InjectionCVSS 8.6

The Themes Coder Ecommerce WordPress plugin through 1.3.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

Impact

Unauthenticated attackers can execute time-based SQL injection to extract sensitive database information or manipulate data.

Remediation

Update Themes Coder Ecommerce plugin to a version newer than 1.3.4.

WeaknessesCWE-89
Authorss4e-io
Template tagswpscancvecve2024wpwordpresswp-pluginsqlitc-ecommercetimebased-sqlivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
FOFA: body="wp-content/plugins/tc-ecommerce/"

Source: ProjectDiscovery

References

2