{"cve":"CVE-2024-27956","epss":{"score":0.94057},"mitre":{"cpes":[],"created":"2024-03-21T17:01:14.106000+00:00","description":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.9,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L"},"cvssV4_0":{}},"mitre_repo_path":"cves/2024/27xxx/CVE-2024-27956.json","references":["https://patchstack.com/articles/critical-vulnerabilities-patched-in-wordpress-automatic-plugin?_s_id=cve","https://patchstack.com/database/vulnerability/wp-automatic/wordpress-automatic-plugin-3-92-0-unauthenticated-arbitrary-sql-execution-vulnerability?_s_id=cve"],"title":"WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability","updated":"2026-04-28T16:09:14.380000+00:00","vendors":[],"weaknesses":["CWE-89"]},"nvd":{"cpes":["cpe:2.3:a:valvepress:automatic:*:*:*:*:*:wordpress:*:*"],"created":"2024-03-21T17:15:08.437000+00:00","description":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.9,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L"},"cvssV4_0":{}},"nvd_repo_path":"2024/CVE-2024-27956.json","references":["https://patchstack.com/articles/critical-vulnerabilities-patched-in-wordpress-automatic-plugin?_s_id=cve","https://patchstack.com/database/vulnerability/wp-automatic/wordpress-automatic-plugin-3-92-0-unauthenticated-arbitrary-sql-execution-vulnerability?_s_id=cve"],"title":null,"updated":"2026-06-17T07:20:40.200000+00:00","vendors":["valvepress","valvepress$PRODUCT$automatic"],"weaknesses":["CWE-89"]},"opencve":{"changes":[{"created":"2025-02-14T16:15:00+00:00","data":[{"details":["valvepress","valvepress$PRODUCT$automatic"],"type":"first_time"},{"details":{"added":["cpe:2.3:a:valvepress:automatic:*:*:*:*:*:wordpress:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["valvepress","valvepress$PRODUCT$automatic"],"removed":[]},"type":"vendors"}],"id":"6766847d-1211-45b0-8211-a13d05ab8f0a"},{"created":"2025-07-15T13:45:00+00:00","data":[{"details":{"added":{},"removed":{},"updated":{"epss":{"new":{"score":0.93359},"old":{"score":0.93357}}}},"type":"metrics"}],"id":"2b4bc940-bdd4-48ce-aad1-1a5400ae7f27"},{"created":"2026-04-28T18:30:00+00:00","data":[{"details":{"new":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0.","old":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0.\n\n"},"type":"description"}],"id":"bbb1d8c4-abb7-4e3e-9a4c-8664f158db40"}],"cpes":{"data":["cpe:2.3:a:valvepress:automatic:*:*:*:*:*:wordpress:*:*"],"providers":["nvd"]},"created":{"data":"2024-03-21T17:01:14.106000+00:00","provider":"mitre"},"description":{"data":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":9.9,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.94057},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{},"provider":null},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://patchstack.com/articles/critical-vulnerabilities-patched-in-wordpress-automatic-plugin?_s_id=cve","https://patchstack.com/database/vulnerability/wp-automatic/wordpress-automatic-plugin-3-92-0-unauthenticated-arbitrary-sql-execution-vulnerability?_s_id=cve"],"providers":["mitre","nvd","vulnrichment"]},"title":{"data":"WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability","provider":"mitre"},"updated":{"data":"2026-04-28T16:09:14.380000+00:00","provider":"mitre"},"vendors":{"data":["valvepress","valvepress$PRODUCT$automatic"],"providers":["nvd"]},"weaknesses":{"data":["CWE-89"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2024-03-21T17:01:14.106000+00:00","description":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0.\n\n","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{}},"references":["https://patchstack.com/articles/critical-vulnerabilities-patched-in-wordpress-automatic-plugin?_s_id=cve","https://patchstack.com/database/vulnerability/wp-automatic/wordpress-automatic-plugin-3-92-0-unauthenticated-arbitrary-sql-execution-vulnerability?_s_id=cve"],"title":"WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability","updated":"2024-08-02T00:41:55.941000+00:00","vendors":[],"vulnrichment_repo_path":"2024/27xxx/CVE-2024-27956.json","weaknesses":[]}}