CVE-2024-0566: Smart Manager < 8.28.0 - Admin+ SQL Injection
The Smart Manager WordPress plugin before 8.28.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0566?
CVE-2024-0566 is classified as a high severity vulnerability due to the potential for SQL injection attacks.
How do I fix CVE-2024-0566?
To fix CVE-2024-0566, update the Smart Manager WordPress plugin to version 8.28.0 or later.
Who is affected by CVE-2024-0566?
CVE-2024-0566 affects users of the Smart Manager WordPress plugin prior to version 8.28.0, particularly those with high privilege user roles.
What impact does CVE-2024-0566 have on my site?
CVE-2024-0566 can allow high privilege users, such as admins, to exploit SQL injection vulnerabilities, potentially compromising the database.
When was CVE-2024-0566 discovered?
CVE-2024-0566 affects versions of the Smart Manager WordPress plugin released before 8.28.0 and was identified in early 2024.