CVE-2024-9156

TI WooCommerce Wishlist <= 2.8.2 - Unauthenticated SQL Injection via lang parameters

The TI WooCommerce Wishlist WordPress plugin through 2.8.2 is vulnerable to SQL Injection due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.


We have discovered 7,079 live websites that are affected by CVE-2024-9156.

Test my site




Affected Software

Product  Ti Woocommerce Wishlist
Category Wordpress Plugins
Vulnerable Domains7,079 live websites (47.45% of Ti Woocommerce Wishlist install base)
Vulnerable Versions
  • from 0 through 2.8.2
Vulnerable Versions Count180 versions ( 97.83% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Oct 10, 2024
  • Updated - Oct 10, 2024

Credits

  • John Castro (finder)
  • WPScan (coordinator)

CVE-2024-9156 usage by Country

United States2,232 websites



Germany836 websites
France366 websites
Cyprus355 websites
Russia309 websites
GB286 websites
Poland184 websites
Italy180 websites
Spain173 websites
Netherlands118 websites

CVE-2024-9156 usage by TLD

.com3,263 websites
.ru245 websites
.de180 websites
.co.uk171 websites
.com.br169 websites
.it157 websites
.fr144 websites
.pl142 websites
.com.au133 websites
.org113 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-9156

Top websites that are affected by CVE-2024-9156. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******************.com United States**,***
***********.com United States***,***
******.sk Slovakia***,***
*****.**.il Germany***,***
*******.pl Poland***,***
**********.com Russia***,***
*************.com United States***,***
*******.no Norway***,***
***************.***.au United States***,***
************.ru Russia***,***
See full domain list

FAQ

CVE-2024-9156 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Ti Woocommerce Wishlist
A total of 7,079 websites have been identified as vulnerable to CVE-2024-9156, discovered through global website indexing conducted by WebTechSurvey.
Ti Woocommerce Wishlist is susceptible to CVE-2024-9156 vulnerability.
Ti Woocommerce Wishlist versions before, and including, 2.8.2 are vulnerable to CVE-2024-9156.