« Volver al listado

CVE-2024-4533

Estado: AnalizadaMedia (6.5)—

The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admin users to perform SQL injection attacks

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-4533",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-4533",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-03-25T18:39:07.198337Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "contact@wpscan.com",
      "affectedData": [
        {
          "vendor": "Unknown",
          "product": "KKProgressbar2 Free ",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "semver",
              "lessThanOrEqual": "1.1.4.2"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2024-05-27T06:15:10.283",
  "references": [
    {
      "url": "https://wpscan.com/vulnerability/c3406236-aaee-480a-8931-79c867252f11/",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "contact@wpscan.com"
    },
    {
      "url": "https://wpscan.com/vulnerability/c3406236-aaee-480a-8931-79c867252f11/",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The KKProgressbar2 Free  WordPress plugin through 1.1.4.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admin users to perform SQL injection attacks"
    },
    {
      "lang": "es",
      "value": "El complemento The KKProgressbar2 Free de WordPress hasta la versión 1.1.4.2 no desinfecta ni escapa un parámetro antes de usarlo en una declaración SQL, lo que permite a los usuarios administradores realizar ataques de inyección SQL."
    }
  ],
  "lastModified": "2026-06-17T08:02:05.230",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.0:*:*:*:free:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2EDE5241-B632-4DB0-AB93-08BA242E884A"
            },
            {
              "criteria": "cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.0.1:*:*:*:free:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "997119BD-A478-4AF0-A271-D3733AB223AB"
            },
            {
              "criteria": "cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.1:*:*:*:free:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F0D884DA-B959-4DAD-AC47-9EF53CA309B4"
            },
            {
              "criteria": "cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.1.1:*:*:*:free:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7469BC8A-1E5B-4661-BE60-D943CE11AB07"
            },
            {
              "criteria": "cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.1.2:*:*:*:free:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "07125506-D462-4154-9ED1-3761DB25821C"
            },
            {
              "criteria": "cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.1.4:*:*:*:free:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3BE6FFA8-AEC0-4BD4-B9DB-3293DCFAC8DF"
            },
            {
              "criteria": "cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.1.4.2:*:*:*:free:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DF5BE688-DD43-47B8-820F-80C0ABAF8FB3"
            },
            {
              "criteria": "cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.2:*:*:*:free:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E0520A7B-E535-4FDB-B3F4-0E4F5CD78D6D"
            },
            {
              "criteria": "cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.3:*:*:*:free:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "340F50CC-4825-40C7-BC6E-25F030FE9C50"
            },
            {
              "criteria": "cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.3.1:*:*:*:free:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7FE0611A-3E59-4C00-842D-A8D538EBC7BB"
            },
            {
              "criteria": "cpe:2.3:a:krzysztof-furtak:kkprogressbar2:1.3.2:*:*:*:free:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "466C9F14-7C0E-4584-BA99-436CCEF77D7E"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "contact@wpscan.com"
}