CVE-2024-38755

HIGH

Designinvento DirectoryPress <3.6.10 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-38755. PoCs published by certuscyber.

AI-analyzed exploit summary The repository contains functional exploit code for multiple WordPress plugin vulnerabilities, including SQL injection (CVE-2014-5182, CVE-2014-5185) and insecure deserialization (CVE-2020-29045). The PoCs include authentication, payload delivery, and data exfiltration logic.

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Designinvento DirectoryPress allows SQL Injection.This issue affects DirectoryPress: from n/a through 3.6.10.

Exploits (1)

github WORKING POC 3 stars
by certuscyber · pythonpoc
https://github.com/certuscyber/cve-pocs/tree/main/CVE-2024-38755

The repository contains functional exploit code for multiple WordPress plugin vulnerabilities, including SQL injection (CVE-2014-5182, CVE-2014-5185) and insecure deserialization (CVE-2020-29045). The PoCs include authentication, payload delivery, and data exfiltration logic.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: WordPress YAWPP plugin <= 1.2, WordPress Quartz plugin <= 1.01.1
Auth required
Prerequisites: WordPress admin/contributor credentials · Vulnerable plugin installed
devstral-2 · analyzed Feb 27, 2026 Full analysis →

Scores

CVSS v3 8.5
EPSS 0.0066
EPSS Percentile 46.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (2)
designinvento/directorypress < 3.6.10
Designinvento/DirectoryPress < 3.6.10
Published Jul 22, 2024
Tracked Since Feb 18, 2026