CVE-2024-1071 WordPress Plugin Vulnerability
Summary
A worrisome security vulnerability has been exposed in the widely-used WordPress plugin known as the Ultimate Member, boasting over 200,000 active installations. This flaw, identified as CVE-2024-1071 and assigned a CVSS score of 9.8 out of 10, was brought to light by security researcher Christiaan Swiers. Consequently, malicious actors without authentication could exploit this flaw to inject supplementary SQL queries into pre-existing ones, leading to the extraction of sensitive data from the database. These attacks employ phishing strategies and malicious injections to take advantage of the Web3 ecosystems reliance on direct wallet interactions, posing a significant threat to both website owners and the security of user assets. CG operates a robust affiliate program with over 10,000 members, encompassing Russian, English, and Chinese speakers.