High severity8.6NVD Advisory· Published Nov 14, 2024· Updated Jun 17, 2026
CVE-2024-9186
CVE-2024-9186
Description
The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit WordPress plugin before 3.3.0 does not sanitize and escape the bwfan-track-id parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- WordPress/WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKitdescription
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/fab29b59-7e87-4289-88dd-ed5520260c26/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.