| CVE ID | CVE-2024-12773 |
|---|---|
| Type | SQL Injection (SQLi) |
| Affected Component | WordPress Plugin Altra Side Menu |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| CVSS Score | 7.2 β High |
| Discovered by | Seckhmet |
A critical SQL Injection was discovered in the WordPress plugin Altra Side Menu. This vulnerability, exploitable with administrator privileges, allows direct attacks on the database with a triple impact on confidentiality, integrity and availability (C:H/I:H/A:H).
An attacker can potentially read all stored data, modify or delete it, and cause complete unavailability of the WordPress service.
Update the Altra Side Menu plugin immediately. Audit access logs to detect any past exploitation. Restrict administrator access and implement a continuous monitoring solution like Seckhmet to be alerted of future vulnerabilities.