CVE-2024-52474
WordPress Express Payments plugin <= 1.1.8 - SQL Injection vulnerability
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Сервис “Экспресс Платежи” Express Payments Module express-pay allows Blind SQL Injection.This issue affects Express Payments Module: from n/a through <= 1.1.8.
| CWE | CWE-89 |
| Vendor | сервис “экспресс платежи” |
| Product | express payments module |
| Published | Nov 28, 2024 |
| Last Updated | Apr 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for сервис “экспресс платежи” express payments module
Be the first to know when new unknown vulnerabilities affecting сервис “экспресс платежи” express payments module are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Сервис “Экспресс Платежи” / Express Payments Module
0 ≤ 1.1.8
References
Credits
LVT-tholv2k | Patchstack Bug Bounty Program