CVE-2024-11267 — Critical SQL Injection (CVSS 8.8)
A high-severity SQL Injection (CVSS 8.8) was discovered in the WordPress plugin JSP Store Locator . This vulnerability is particularly dangerous because it is exploitable with low user privileges (PR:L) , without victim interaction, and results in a triple critical impact on confidentiality, integrity and availability .
Any registered user on a WordPress site using this plugin can potentially read, modify or delete all data in the database, or even take the site offline.
Immediately update or uninstall the JSP Store Locator plugin. Check database logs for any past exploitation. Deploy a continuous WordPress monitoring solution to anticipate this type of threat as soon as a CVE is published.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
