CVE-2024-9879: Website File Changes < 2.1.1 - Authenticated SQL Injection
The Melapress File Monitor WordPress plugin before 2.1.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9879?
CVE-2024-9879 is categorized as a high severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2024-9879?
To fix CVE-2024-9879, update the Melapress File Monitor WordPress plugin to version 2.1.1 or later.
Who is affected by CVE-2024-9879?
Admins using the Melapress File Monitor WordPress plugin before version 2.1.1 are affected by CVE-2024-9879.
What type of attack does CVE-2024-9879 enable?
CVE-2024-9879 enables SQL injection attacks due to improper sanitization of parameters.
What should I do if I can't update the plugin for CVE-2024-9879?
If an update for the Melapress File Monitor plugin cannot be applied, immediately restrict access and monitor database interactions to mitigate risks associated with CVE-2024-9879.