{ "id": "CVE-2024-1068", "sourceIdentifier": "contact@wpscan.com", "published": "2024-03-11T18:15:17.847", "lastModified": "2024-03-12T12:40:13.500", "vulnStatus": "Awaiting Analysis", "cveTags": [], "descriptions": [ { "lang": "en", "value": "The 404 Solution WordPress plugin before 2.35.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admins." }, { "lang": "es", "value": "El complemento 404 Solution de WordPress anterior a 2.35.8 no sanitiza ni escapa adecuadamente un par\u00e1metro antes de usarlo en una declaraci\u00f3n SQL, lo que genera una inyecci\u00f3n de SQL explotable por usuarios con privilegios elevados, como los administradores." } ], "metrics": {}, "references": [ { "url": "https://wpscan.com/vulnerability/25e3c1a1-3c45-41df-ae50-0e20d86c5484/", "source": "contact@wpscan.com" } ] }