CVE-2024-13726 is a critical SQL injection vulnerability affecting the Coder WordPress plugin up to version 1.3.4, specifically within the "themescoder themes_coder" product. With a CVSS score of 8.6 (High), this vulnerability allows unauthenticated attackers to execute SQL injection attacks remotely with low complexity, potentially leading to full compromise of confidentiality. While not currently listed in CISA's KEV catalog, exploit intelligence indicates the availability of Nuclei templates, and community discussion is high with 10 mentions, suggesting significant interest. There is no evidence of active exploitation or Metasploit/ExploitDB entries at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.3.4CPE matchmatch criteria | cpe:2.3:a:themescoder:themes_coder:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.