WP-Recall – Registration, Profile, Commerce & More, CVE-2024-9770
- CVE, Research URL
- Published on
- Mar 25, 2025
- Research Description
- The WP-Recall WordPress plugin before 16.26.12 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
- Affected versions
-
max 16.26.12.
- Status
-
vulnerable
| Previous vulnerability researches |
|---|
| SEO Backlink Monitor (CVE-2024-29907) , Jun 06, 2024 |
| SEO Backlink Monitor (CVE-2025-53456) , Oct 11, 2025 |
| SEO Backlink Monitor (CVE-2025-53457) , Apr 25, 2026 |