| CVE ID | CVE-2024-11269 |
|---|---|
| Type | SQL Injection (SQLi) |
| Affected Component | WordPress Plugin AHAthat |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| CVSS Score | 6.5 β Medium |
| Discovered by | Seckhmet |
A SQL Injection was discovered in the WordPress plugin AHAthat. Unlike other CVEs from this plugin, this one is exploitable with low user privileges (PR:L), significantly broadening the attack surface.
Any registered WordPress user can potentially exfiltrate confidential data from the database, including personal data, hashed credentials, or sensitive business information.
Update the AHAthat plugin immediately. Limit the number of active user accounts on your WordPress installations. Monitor for abnormal SQL queries via continuous monitoring.