CVE-2024-13322 is a high-severity SQL Injection vulnerability affecting the Ads Pro Plugin – Multi-Purpose WordPress Advertising Manager plugin, versions up to and including 4.88. Unauthenticated attackers can exploit this flaw by manipulating the 'a_id' parameter to extract sensitive information from the database. With a CVSS score of 7.5 (High) and a FAUCET Risk Score of 98/100, this vulnerability poses a significant risk due to its low attack complexity and high potential for data compromise. While not listed in CISA's KEV catalog, Nuclei templates exist for this vulnerability, indicating readily available exploit code. Community discussion is notably high, suggesting active awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.89CPE matchmatch criteria | cpe:2.3:a:scripteo:ads_pro:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.