CVE-2024-11269

The AHAthat Plugin WordPress plugin through 1.6 does not sanitize and escape a parameter before using it in a SQL statement, allowing Admin to perform SQL injection attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mitchelllevy:ahathat:*:*:*:*:*:wordpress:*:*

History

12 Jun 2025, 16:58

Type Values Removed Values Added
CPE cpe:2.3:a:mitchelllevy:ahathat:*:*:*:*:*:wordpress:*:*
CWE CWE-89
First Time Mitchelllevy ahathat
Mitchelllevy
References () https://wpscan.com/vulnerability/3ad89687-adb0-4c45-938c-0c18fda7f36f/ - () https://wpscan.com/vulnerability/3ad89687-adb0-4c45-938c-0c18fda7f36f/ - Exploit, Third Party Advisory

20 May 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2
References () https://wpscan.com/vulnerability/3ad89687-adb0-4c45-938c-0c18fda7f36f/ - () https://wpscan.com/vulnerability/3ad89687-adb0-4c45-938c-0c18fda7f36f/ -

16 May 2025, 14:43

Type Values Removed Values Added
Summary
  • (es) El complemento AHAthat de WordPress hasta la versión 1.6 no depura ni escapa un parámetro antes de usarlo en una declaración SQL, lo que permite al administrador realizar ataques de inyección SQL.

15 May 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-15 20:15

Updated : 2025-06-12 16:58


NVD link : CVE-2024-11269

Mitre link : CVE-2024-11269

CVE.ORG link : CVE-2024-11269


JSON object : View

Products Affected

mitchelllevy

  • ahathat
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')