Skip to content

Known CVE

CZ Loan Management <= 1.1 - SQL Injection

The CZ Loan Management WordPress plugin through 1.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2024-5975

Critical2024CVSS 9.1

time-based-sqli · cve2024 · wpscan · wp-plugin · wordpress · wp · cz-loan-management · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website