Record summary

CVE-2024-6205 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

The PayPlus Payment Gateway WordPress plugin before 6.6.9 does not properly sanitise and escape a parameter before using it in a SQL statement via a WooCommerce API route available to unauthenticated users, leading to an SQL injection vulnerability.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 22, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 19, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

PayPlus Payment Gateway

Default status: unaffected

CVE ListBefore 6.6.9affected
VulnCheckVersion data not supplied

Default status: unaffected

CVE ListBefore 6.6.9affected

Proofs of concept

1

Repository PoCs

GitHubj3r1ch0123/CVE-2024-6205Repository PoCby j3r1ch0123Stars: 1Not analyzed2 files

1.3 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALPayPlus Payment Gateway < 6.6.9 - SQL InjectionCVSS 9.8

The PayPlus Payment Gateway WordPress plugin before 6.6.9 does not properly sanitise and escape a parameter before using it in a SQL statement via a WooCommerce API route available to unauthenticated users, leading to an SQL injection vulnerability.

Impact

Unauthenticated attackers can execute time-based SQL injection through WooCommerce API routes to extract sensitive payment information, customer data, and database credentials.

Remediation

Update PayPlus Payment Gateway plugin to version 6.6.9 or later to address the SQL injection vulnerability.

WeaknessesCWE-89
Authorss4e-io
Template tagstime-based-sqliwpscancvecve2024sqliwordpresswp-pluginwppayplus-paymentvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Source: ProjectDiscovery

References

2