VYPR

Action Network

by Jonathankissam

CVEs (1)

  • CVE-2024-2954HigMar 27, 2024
    risk 0.47cvss 7.2epss 0.01

    The Action Network plugin for WordPress is vulnerable to SQL Injection via the 'bulk-action' parameter in version 1.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…