Record summary

CVE-2024-8625 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.

Description

The TS Poll WordPress plugin before 2.4.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 21, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

TS Poll

Default status: unaffected

CVE ListBefore 2.4.0affected

Default status: unknown

CVE ListBefore 2.4.0affected

Nuclei templates

1
ProjectDiscoveryHIGHWordPress TS Poll < 2.4.0 - SQL InjectionCVSS 7.2

WordPress TS Poll plugin < 2.4.0 contains a SQL injection caused by lack of sanitization and escaping of a parameter before using it in a SQL statement, letting attackers perform SQL injection attacks, exploit requires admin privileges.

Impact

Attackers can execute arbitrary SQL commands, potentially leading to data theft, modification, or deletion.

Remediation

Update to version 2.4.0 or later.

WeaknessesCWE-89
Authorsriteshs4hu
Template tagscvecve2024wordpresswp-pluginwpts-pollsqliauthenticated
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:total-soft:ts_poll:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2