WP-Recall – Registration, Profile, Commerce & More, CVE-2024-9770
- CVE, Research URL
- Published on
- Mar 25, 2025
- Research Description
- The WP-Recall WordPress plugin before 16.26.12 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
- Affected versions
-
max 16.26.12.
- Status
-
vulnerable
| Previous vulnerability researches |
|---|
| WooCommerce Additional Fees On Checkout (Free) (CVE-2024-12395) , Dec 18, 2024 |
| WooCommerce Additional Fees On Checkout (Free) (CVE-2025-57903) , Apr 25, 2026 |