CVE-2024-30490
WordPress ProfileGrid plugin <= 5.7.8 - SQL Injection vulnerability
Record summary
CVE-2024-30490 has a selected CVSS score of 9.3 (critical); EIP currently links 1 Nuclei template.
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 8, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Through 5.7.8 | affected |
profilegridBrowse metagauss / profilegridDefault status: unaffected | CVE List | Through 5.7.8 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALProfileGrid <= 5.7.8 - SQL Injection
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.7.8 due to insufficient escaping on the user supplied 'search' parameter and lack of sufficient preparation on the existing SQL query.
Impact
Attackers can execute arbitrary SQL queries, potentially leading to data theft, data tampering, or database compromise.
Remediation
Update to ProfileGrid version 5.7.9 or later.
Source: ProjectDiscovery