CVE-2024-27956

Published Mar 21, 2024

Last updated 2 months ago

CVSS critical 9.9
WordPress
ValvePress

Overview

AI description

Generated using AI and has not been reviewed by Intruder. May contain errors.

CVE-2024-27956 is an SQL Injection vulnerability affecting the WordPress Automatic plugin by ValvePress, specifically versions up to 3.92.0. The vulnerability stems from improper neutralization of special elements used in an SQL command. This flaw allows attackers to inject malicious SQL code, potentially leading to unauthorized access to websites, creation of admin-level user accounts, uploading malicious files, and ultimately, taking full control of affected sites. It has been reported that attackers are actively exploiting this vulnerability.

Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0.
Source
audit@patchstack.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

audit@patchstack.com
CWE-89

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

27

  1. 🚨 Hackers are abusing WordPress mu-plugins—a hidden auto-run directory—to inject malware, hijack links, and redirect users to scam sites. Also, add these to the list of 2024's major WordPress threats: CVE-2024-27956 | SQL injection CVE-2024-25600 | RCE in Bricks theme https://t

    @TheHackersNews

    31 Mar 2025

    13318 Impressions

    59 Retweets

    106 Likes

    19 Bookmarks

    1 Reply

    2 Quotes

  2. #今日の脆弱性 #EPSS CVE-2024-27956 ValvePress(WordPressのPlugin)のSQLiの脆弱性が上昇傾向にあります、が、epss=0.55374と現状では静観レベル。 https://t.co/5YP6Wsxdm1

    @papa_anniekey

    16 Feb 2025

    397 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  3. امشب بچه ها یک لایو داریم ساعت ۸ برای exploit اپیزود این هفته که درمورد CVE-2024-27956 بود https://t.co/DZbh3dng8o

    @soltanali0

    3 Jan 2025

    88 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 Week 33 | GOTOCVE 🚨 This week we’re diving into CVE-2024-27956 in the WP-Aitomatic WordPress plugin! 🔍 SQL Injection vulnerability that could give attackers admin access. 🔓 Check out the live demo on our Telegram channel! 🔗 https://t.co/DZbh3dng8o #GOTOCVE #CVE202427956

    @soltanali0

    2 Jan 2025

    55 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. [1day1line] CVE-2024-27956: SQL Injection Vulnerability in WordPress's Automatic This vulnerability was exploited by WordPress' SQL Injection. The vulnerability occurred by directly executing the value of a variable passed by the user as a SQL query. https://t.co/CKBttp2wEu

    @hackyboiz

    20 Nov 2024

    302 Impressions

    1 Retweet

    3 Likes

    1 Bookmark

    0 Replies

    0 Quotes

Configurations