S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Dec 3, 2024

CVE-2024-9186 Scanner

CVE-2024-9186 Scanner - SQL Injection vulnerability in FunnelKit Automation By Autonami

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.4k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
2
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-9186
8.6
CVSShigh
Exploitable remotely over the internet · no authentication required.

The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit WordPress plugin before 3.3.0 does not sanitize and escape the bwfan-track-id parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit
AFFECTED< 3.3.0SAFE ✓≥ 3.3.0
funnelkit_automationsby funnelkit
AFFECTED< 3.3.0SAFE ✓≥ 3.3.0
Updated Aug 22, 2026View on NVD →
Detail

FunnelKit Automation By Autonami is a WordPress plugin used primarily for automating marketing workflows. It integrates seamlessly with WooCommerce, enabling users to recover abandoned carts, send newsletters, and automate email marketing campaigns. This tool is widely adopted by online stores to streamline their marketing processes and boost sales efficiency.

The vulnerability involves an SQL Injection issue present in versions of FunnelKit Automation By Autonami before 3.3.0. The plugin fails to sanitize and escape the "bwfan-track-id" parameter, leading to the potential exploitation of this flaw by malicious actors. This allows attackers to craft SQL queries, thereby gaining unauthorized access to sensitive database information.

Exploitation occurs through the "bwfan-track-id" parameter. Malicious actors can inject crafted payloads to execute time-based SQL queries. The endpoint allows unauthenticated users to perform SQL commands that manipulate or exfiltrate database records without proper authorization or validation.

If successfully exploited, attackers could compromise the integrity and confidentiality of the application's data. It may lead to unauthorized data access, leakage of sensitive information, or in some cases, disruption of the affected service's database operations.

REFERENCES

Solution Advice
  • Update the FunnelKit Automation By Autonami plugin to version 3.3.0 or later.
  • Implement parameterized queries or prepared statements in the affected codebase.
  • Sanitize and validate all user inputs to mitigate injection risks.
  • Regularly monitor plugins for vulnerabilities and apply updates promptly.
  • Conduct regular security audits to identify and remediate potential vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-9186 Scanner - SQL Injection vulnerability in FunnelKit Automation By Autonami S4E