CVE-2024-49609

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brandon White Author Discussion author-discussion allows Blind SQL Injection.This issue affects Author Discussion: from n/a through <= 0.2.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:brandonwhite:author_discussion:*:*:*:*:*:wordpress:*:*

History

23 Apr 2026, 15:19

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : 8.5

01 Apr 2026, 16:18

Type Values Removed Values Added
Summary (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brandon White Author Discussion allows Blind SQL Injection.This issue affects Author Discussion: from n/a through 0.2.2. (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brandon White Author Discussion author-discussion allows Blind SQL Injection.This issue affects Author Discussion: from n/a through <= 0.2.2.
References
  • {'url': 'https://patchstack.com/database/vulnerability/author-discussion/wordpress-author-discussion-plugin-0-2-2-sql-injection-vulnerability?_s_id=cve', 'tags': ['Third Party Advisory'], 'source': 'audit@patchstack.com'}
  • () https://patchstack.com/database/Wordpress/Plugin/author-discussion/vulnerability/wordpress-author-discussion-plugin-0-2-2-sql-injection-vulnerability?_s_id=cve -

24 Oct 2024, 15:25

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.5
v2 : unknown
v3 : 8.8
CPE cpe:2.3:a:brandonwhite:author_discussion:*:*:*:*:*:wordpress:*:*
First Time Brandonwhite author Discussion
Brandonwhite
References () https://patchstack.com/database/vulnerability/author-discussion/wordpress-author-discussion-plugin-0-2-2-sql-injection-vulnerability?_s_id=cve - () https://patchstack.com/database/vulnerability/author-discussion/wordpress-author-discussion-plugin-0-2-2-sql-injection-vulnerability?_s_id=cve - Third Party Advisory

21 Oct 2024, 17:09

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando SQL ('Inyección SQL') en Brandon White Author Discussion permite la inyección SQL ciega. Este problema afecta a Author Discussion: desde n/a hasta 0.2.2.

20 Oct 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-20 10:15

Updated : 2026-04-23 15:19


NVD link : CVE-2024-49609

Mitre link : CVE-2024-49609

CVE.ORG link : CVE-2024-49609


JSON object : View

Products Affected

brandonwhite

  • author_discussion
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')