CVE-2024-8625
TS Poll – Survey, Versus Poll, Image Poll, Video Poll < 2.4.0 - Admin+ SQL Injection
Record summary
CVE-2024-8625 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.
Description
The TS Poll WordPress plugin before 2.4.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 21, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
TS PollDefault status: unaffected | CVE List | Before 2.4.0 | affected |
Default status: unknown | CVE List | Before 2.4.0 | affected |
Nuclei templates
1ProjectDiscoveryHIGHWordPress TS Poll < 2.4.0 - SQL InjectionCVSS 7.2
WordPress TS Poll plugin < 2.4.0 contains a SQL injection caused by lack of sanitization and escaping of a parameter before using it in a SQL statement, letting attackers perform SQL injection attacks, exploit requires admin privileges.
Impact
Attackers can execute arbitrary SQL commands, potentially leading to data theft, modification, or deletion.
Remediation
Update to version 2.4.0 or later.
Source: ProjectDiscovery