| CVE ID | CVE-2024-11372 |
|---|---|
| Type | SQL Injection (SQLi) |
| Affected Component | WordPress Plugin Connexion Logs |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| CVSS Score | 7.2 β High |
| Discovered by | Seckhmet |
A SQL Injection was discovered in the WordPress plugin Connexion Logs, a tool designed to log connections on WordPress sites. The flaw allows an attacker with administrator rights to manipulate SQL queries, resulting in a critical impact on confidentiality, integrity and availability.
A plugin designed to improve security containing a critical vulnerability itself perfectly illustrates the need to regularly audit the entire WordPress ecosystem, including security tools.
Update or disable the Connexion Logs plugin. Implement continuous WordPress plugin monitoring with Seckhmet to be notified in real time of any new vulnerability affecting your perimeter.