S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Apr 30, 2024

CVE-2024-1698 Scanner

CVE-2024-1698 scanner - SQL Injection vulnerability in NotificationX

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
3
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-1698
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in all versions up to, and including, 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Barby wpdevteam
0
notificationxby wpdeveloper
0
Updated Aug 22, 2026View on NVD →
Detail

NotificationX is a WordPress plugin designed to enhance user engagement by providing various notification features such as FOMO, Social Proof, WooCommerce Sales Popup, and Notification Bar. It is utilized by website owners and administrators to display notifications and alerts to site visitors, thereby increasing conversion rates and user interaction on WordPress-based websites.

The detected vulnerability in NotificationX is a SQL Injection flaw present in versions up to and including 2.8.2. This vulnerability arises due to insufficient input validation and inadequate preparation of SQL queries, allowing unauthenticated attackers to inject malicious SQL code via the 'type' parameter. Exploiting this vulnerability enables attackers to manipulate SQL queries and potentially extract sensitive information from the database.

The vulnerability is exploited by sending a crafted HTTP POST request to the '/wp-json/notificationx/v1/analytics' endpoint of the WordPress site hosting the NotificationX plugin. The malicious payload is included in the 'type' parameter of the JSON payload, allowing attackers to inject SQL code such as boolean-based blind SQL injection payloads. Successful exploitation results in the execution of arbitrary SQL queries against the WordPress site's database, potentially leading to data leakage or data manipulation.

Exploiting the SQL Injection vulnerability in NotificationX can have severe consequences, including unauthorized access to sensitive data stored in the WordPress site's database, disclosure of personally identifiable information (PII), compromise of user credentials, and potential data loss or corruption. Attackers can leverage the injected SQL queries to extract, modify, or delete sensitive information, undermining the confidentiality, integrity, and availability of the affected WordPress site.

Protect your WordPress site from the risks posed by the SQL Injection vulnerability in NotificationX by utilizing the comprehensive security scanning capabilities of the S4E platform. Join our platform to identify and remediate critical vulnerabilities like CVE-2024-1698, ensuring the security and integrity of your WordPress-based web applications and safeguarding your sensitive data from unauthorized access and exploitation.

 

References

Solution Advice
  • Update NotificationX plugin to the latest patched version (>= 2.8.3) to mitigate the SQL Injection vulnerability.
  • Implement proper input validation and parameterized SQL queries to prevent SQL Injection attacks in WordPress plugins and themes.
  • Regularly monitor web server logs and audit database queries for suspicious or unauthorized activity indicative of SQL Injection attempts.
  • Deploy web application firewalls (WAFs) or security plugins capable of detecting and blocking SQL Injection attacks in real-time.
  • Educate WordPress site administrators and developers about secure coding practices and the importance of input sanitization to prevent SQL Injection vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.