The Fancy Product Designer WordPress plugin before 6.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by adminstrators.
History

Mon, 05 May 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Radykal
Radykal fancy Product Designer
Weaknesses CWE-89
CPEs cpe:2.3:a:radykal:fancy_product_designer:*:*:*:*:*:wordpress:*:*
Vendors & Products Radykal
Radykal fancy Product Designer

Thu, 08 Aug 2024 22:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-03-18T19:05:42.966Z

Updated: 2024-08-08T20:38:59.032Z

Reserved: 2024-01-09T15:47:13.237Z

Link: CVE-2024-0365

cve-icon Vulnrichment

Updated: 2024-08-01T18:04:49.725Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-18T19:15:06.253

Modified: 2025-05-05T15:15:56.690

Link: CVE-2024-0365

cve-icon Redhat

No data.