WP-Recall – Registration, Profile, Commerce & More, CVE-2024-9770
- CVE, Research URL
- Published on
- Mar 25, 2025
- Research Description
- The WP-Recall WordPress plugin before 16.26.12 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
- Affected versions
-
max 16.26.12.
- Status
-
vulnerable
| Previous vulnerability researches |
|---|
| Tainacan Interface (CVE-2024-3867) , Jun 10, 2024 |