CVE-2024-6027 is a time-based SQL Injection vulnerability affecting the Themify – WooCommerce Product Filter plugin for WordPress, impacting all versions up to and including 1.4.9. This high-severity vulnerability (CVSS 7.5) allows unauthenticated attackers to extract sensitive database information due to insufficient input sanitization. While no public exploits or active exploitation have been observed, and community discussion is minimal, the potential for data exfiltration remains a significant concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.0CPE matchmatch criteria | cpe:2.3:a:themify:product_filter:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.