CVE-2024-9887
CVE-2024-9887 is a SQL Injection vulnerability affecting the Login using WordPress Users (WP as SAML IDP) plugin. This flaw allows attackers with Administrator-level access to inject malicious SQL code. The WordPress plugin, in versions up to 1.15.6, fails to properly sanitize the 'id' parameter, creating the vulnerability.
The SQL Injection can be exploited to extract sensitive data from the database. Despite its low SVRS score of 30, the security risk is still significant as it could potentially leak confidential user data or compromise the entire WordPress installation. Successful exploitation requires authenticated access with administrative privileges. Immediate patching is recommended to mitigate the risk of unauthorized data access. While tagged "In The Wild," the relatively low SVRS suggests the vulnerability may not be actively exploited on a wide scale, however, vigilance is crucial.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.