CVE-2024-49681

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows SQL Injection.This issue affects WP Sessions Time Monitoring Full Automatic: from n/a through <= 1.0.9.
CVSS

No CVSS.

Configurations

No configuration.

History

01 Apr 2026, 16:18

Type Values Removed Values Added
Summary (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SWIT WP Sessions Time Monitoring Full Automatic allows SQL Injection.This issue affects WP Sessions Time Monitoring Full Automatic: from n/a through 1.0.9. (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows SQL Injection.This issue affects WP Sessions Time Monitoring Full Automatic: from n/a through <= 1.0.9.
References
  • {'url': 'https://patchstack.com/database/vulnerability/activitytime/wordpress-wp-sessions-time-monitoring-full-automatic-plugin-1-0-9-sql-injection-vulnerability?_s_id=cve', 'source': 'audit@patchstack.com'}
  • () https://patchstack.com/database/Wordpress/Plugin/activitytime/vulnerability/wordpress-wp-sessions-time-monitoring-full-automatic-plugin-1-0-9-sql-injection-vulnerability?_s_id=cve -
CVSS v2 : unknown
v3 : 9.3
v2 : unknown
v3 : unknown

25 Oct 2024, 12:56

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando SQL ('Inyección SQL') en SWIT WP Sessions Time Monitoring Full Automatic permite la inyección SQL. Este problema afecta a WP Sessions Time Monitoring Full Automatic: desde n/a hasta 1.0.9.

24 Oct 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-24 12:15

Updated : 2026-04-15 00:35


NVD link : CVE-2024-49681

Mitre link : CVE-2024-49681

CVE.ORG link : CVE-2024-49681


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')