WordPress Plugin Security Update Advisory (CVE-2024-49681)

Overview

 

An update has been released to address vulnerabilities in WordPress WP Sessions Time Monitoring Full Automatic Plugin. Users of the affected versions are advised to update to the latest version.

 

Affected Products

 

CVE-2024-49681

  • WP Sessions Time Monitoring Full Automatic versions: ~ 1.0.9 (inclusive)

 

 

Resolved Vulnerabilities

 

SQL injection vulnerability in the SWIT WP Sessions Time Monitoring Full Automatic plugin (CVE-2024-49681)

 

Vulnerability Patches

 

Vulnerability Patches have been made available with the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2024-49681

  • WP Sessions Time Monitoring Full Automatic version: 1.1.0

 

 

Referenced Sites

 

[1] CVE-2024-49681 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-49681

[2] WordPress WP Sessions Time Monitoring Full Automatic Plugin <= 1.0.9 is vulnerable to SQL Injection

https://patchstack.com/database/vulnerability/activitytime/wordpress-wp-sessions-time-monitoring-full-automatic-plugin-1-0-9-sql-injection-vulnerability?_s_id=cve