CVE-2024-56247

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AF themes WP Post Author wp-post-author allows SQL Injection.This issue affects WP Post Author: from n/a through <= 3.8.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:afthemes:wp_post_author:*:*:*:*:*:wordpress:*:*

History

01 Apr 2026, 16:21

Type Values Removed Values Added
References
  • {'url': 'https://patchstack.com/database/wordpress/plugin/wp-post-author/vulnerability/wordpress-wp-post-author-plugin-3-8-2-sql-injection-vulnerability?_s_id=cve', 'tags': ['Third Party Advisory'], 'source': 'audit@patchstack.com'}
  • () https://patchstack.com/database/Wordpress/Plugin/wp-post-author/vulnerability/wordpress-wp-post-author-plugin-3-8-2-sql-injection-vulnerability?_s_id=cve - Third Party Advisory
Summary (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AF themes WP Post Author allows SQL Injection.This issue affects WP Post Author: from n/a through 3.8.2. (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AF themes WP Post Author wp-post-author allows SQL Injection.This issue affects WP Post Author: from n/a through <= 3.8.2.
CVSS v2 : unknown
v3 : 7.6
v2 : unknown
v3 : 7.2

07 Feb 2025, 15:44

Type Values Removed Values Added
References () https://patchstack.com/database/wordpress/plugin/wp-post-author/vulnerability/wordpress-wp-post-author-plugin-3-8-2-sql-injection-vulnerability?_s_id=cve - () https://patchstack.com/database/wordpress/plugin/wp-post-author/vulnerability/wordpress-wp-post-author-plugin-3-8-2-sql-injection-vulnerability?_s_id=cve - Third Party Advisory
First Time Afthemes wp Post Author
Afthemes
Summary
  • (es) Vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando SQL ('Inyección SQL') en AF themes WP Post Author permiteLa inyección SQL. Este problema afecta a WP Post Author: desde n/a hasta 3.8.2.
CPE cpe:2.3:a:afthemes:wp_post_author:*:*:*:*:*:wordpress:*:*

02 Jan 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-02 12:15

Updated : 2026-04-01 16:21


NVD link : CVE-2024-56247

Mitre link : CVE-2024-56247

CVE.ORG link : CVE-2024-56247


JSON object : View

Products Affected

afthemes

  • wp_post_author
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')