S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Oct 29, 2024

CVE-2024-9796 Scanner

CVE-2024-9796 scanner - SQL Injection vulnerability in WordPress WP-Advanced-Search

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.4k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
3
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-9796
9.8
CVSSmedium
Requires local system access · no authentication required.

The WP-Advanced-Search WordPress plugin before 3.3.9.2 does not sanitize and escape the t parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

Attack Vector
Local
Privileges Req.
None
User Interaction
None
Affected
WP-Advanced-Search
AFFECTED< 3.3.9.2SAFE ✓≥ 3.3.9.2
wp-advanced-searchby wp-advanced-search_project
AFFECTED< 3.3.9.2SAFE ✓≥ 3.3.9.2
Updated Aug 22, 2026View on NVD →
Detail

WordPress WP-Advanced-Search is a plugin used by WordPress website owners to enhance their search capabilities, providing users with more advanced and customizable search options. It is primarily used by website administrators and developers looking to improve site navigation and user experience. With features supporting tailored search queries, it integrates with multiple WordPress themes and setups. WP-Advanced-Search is a widely used plugin in various industries, including e-commerce and blogging. The plugin has been installed across a large number of WordPress sites due to its flexibility and integration capabilities.

This SQL Injection vulnerability in the WP-Advanced-Search plugin allows attackers to manipulate SQL queries by injecting malicious SQL code. Unauthenticated users can exploit this vulnerability due to the lack of proper escaping and validation of user input, making sensitive data extraction possible. An attacker can leverage this vulnerability to access confidential information, potentially compromising the site’s database integrity. The ease of exploitation, combined with the severity of data access, renders this vulnerability critical.

The SQL Injection vulnerability in WP-Advanced-Search affects a specific endpoint that processes user search queries. The vulnerable endpoint fails to sanitize and properly escape user inputs, allowing attackers to insert arbitrary SQL commands. By targeting the “q” parameter, malicious users can append commands that manipulate database queries. This vulnerability is primarily found in the autocompletion-PHP5.5.php file within the plugin's autocompletion feature. Exploiting this flaw, attackers can gain unauthorized access to data within the wp_users table, which can include sensitive information like usernames and hashed passwords.

If exploited, this SQL Injection vulnerability could lead to unauthorized data access, including user credentials and sensitive site information. Attackers may use this data to compromise the entire WordPress site, leading to further unauthorized access and potential defacement. Furthermore, the exposure of database content can compromise user privacy and trust in the site, especially if personal data is exposed. Long-term effects may include loss of reputation, financial costs, and increased risk of phishing attacks against site users.

S4E offers a comprehensive platform to help identify and mitigate vulnerabilities in your digital assets, including WordPress plugins like WP-Advanced-Search. With automated and regularly updated security checks, users can quickly pinpoint weaknesses, receive clear and actionable reports, and protect sensitive data from exploitation. Our platform is designed for both novices and seasoned professionals, making cybersecurity accessible and efficient. Start securing your site today with S4E to gain peace of mind and keep your online presence resilient.

References:

Solution Advice
  • Update the WP-Advanced-Search plugin to the latest version or apply available patches.
  • Regularly sanitize and validate all user inputs to prevent SQL Injection vulnerabilities.
  • Consider disabling or limiting the autocomplete feature if not essential.
  • Implement Web Application Firewall (WAF) to help filter out malicious requests targeting your site.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.