s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2024-55986

📛 CVE Title

WordPress Service plugin <= 1.0.4 - SQL Injection vulnerability

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tiny13 Service service allows Blind SQL Injection.This issue affects Service: from n/a through <= 1.0.4.

Overview

State
PUBLISHED
Assigner (CNA)
Patchstack
CVSS severity
HIGH
CVSS score
CVSS 8.5 / 10 8.5 8.5 / 10
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
Effective score
8.5 / 10 HIGH source: CNA overview
CWE(s)
CWE-89
Reserved
2024-12-14
Published
2024-12-16 15:31 UTC
Last updated
2026-04-28 18:10 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/55xxx/CVE-2024-55986.json
Linked Threat
CVE-2024-55986 — Service <= 1.0.4 - Authenticated (Subscriber+) SQL Injection

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2024-12-16 15:15:25 UTC
NVD last modified
2026-06-17 08:11:32 UTC
NVD CVSS v3.1
CVSS 8.5 / 10 8.5 8.5 / 10 HIGH source: audit@patchstack.com
NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
Exploitability subscore
3.1 / 10
Impact subscore
4.7 / 10
EPSS score
0.0048 (probability of exploitation in next 30 days)
EPSS percentile
37.83% vs all CVEs — higher = more likely to be exploited, as of 2026-06-30

NVD / KEV / EPSS data refreshed 2026-06-30 19:06 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2024-52886
Assigner
Patchstack
Published
Dec 16, 2024, 2:31:17 PM
Updated
Apr 28, 2026, 4:10:53 PM
EUVD base score (CVSS 3.1)
8.5 / 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
EUVD-reported EPSS
0.4400
Vendors
serviceonline, tiny13
Products
Service (n/a ≤1.0.4)
Service (0 ≤1.0.4)
Aliases
GHSA-j2f8-56pc-7gmr

ENISA description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tiny13 Service service allows Blind SQL Injection.This issue affects Service: from n/a through <= 1.0.4.

EUVD references (1)

Affected products (1)

VendorProductVersionsPlatforms
tiny13 Service 0 (affected)

Vendor references (1)

References embedded in the original CVE record by the assigning CNA.

MITRE references (1) cveawg.mitre.org

Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.

Web references (0)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

No web references attached yet.

NVD-tagged references (1)

Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.

Indicators (2)

IOCs linked to the auto-promoted Threat row.

TypeValueVirusTotalAttached
domain injection.this no local data 2026-05-18 21:19 UTC
cve CVE-2024-55986 no local data 2026-06-06 14:07 UTC

Flagged vendors

    Remediations (21)

    Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

    • web:nvd.nist.gov

      Description In the Linux kernel, the following vulnerability has been resolved: HID: core: Fix assumption that Resolution Multipliers must be in Logical Collections A report in 2019 by the syzbot fuzzer was found to be connected to two errors in the HID core associated with Resolution Multipliers. One of the errors was fixed by commit ea427a222d8b ("HID: core: Fix deadloop in hid_apply ...

      2026-08-09 22:26 UTC
    • web:cybersecuritynews.com

      The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued Binding Operational Directive (BOD) 26-04, titled "Prioritizing Security Updates Based on Risk," compelling all Federal Civilian Executive Branch (FCEB) agencies to remediate the most dangerous known exploited vulnerabilities within just three calendar days.

      2026-08-09 22:26 UTC
    • web:learn.microsoft.com

      Learning path Learn how Microsoft supports secure software development as part of a cybersecurity solution - Training Secure software development means integrating security into each phase of your development lifecycle, from requirements analysis to maintenance. Microsoft provides many services that can help you develop more secure code and deploy a more secure application in the cloud. This ...

      2026-08-09 22:26 UTC
    • web:www.oracle.com

      This Critical Patch Update contains 1449 new security patches across the product families listed below. Please note that a My Oracle Support (MOS) note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at July 2026 Critical Patch Update: Executive Summary and Analysis.

      2026-08-09 22:26 UTC
    • web:www.oracle.com

      Prior Critical Patch Update and Critical Security Patch Update advisories should be reviewed for information regarding earlier published security patches. Refer to Critical Patch Updates, Critical Security Patch Updates, Security Alerts and Bulletins for information about Oracle Security advisories.

      2026-08-09 22:26 UTC
    • web:www.nist.gov

      NIST maintains the National Vulnerability Database (NVD), a repository of information on software and hardware flaws that can compromise computer security. This is a key piece of the nation's cybersecurity infrastructure.

      2026-08-09 22:26 UTC
    • web:app.opencve.io

      Explore the latest vulnerabilities and security issues in the CVE database

      2026-08-09 22:26 UTC
    • Wordfence remediation: Service
      Wordfence

      No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.

      2026-06-06 14:07 UTC
    • web:www.pcworld.com

      Windows 11's Secure Boot fix update finally rolls out to more PCs Important security certificates for Windows 11 will soon expire for many users.

      2026-05-22 10:58 UTC
    • web:www.esri.com

      Key highlights The ArcGIS Server Security 2025 update 2 is available This patch resolves 10 Medium severity vulnerabilities This security patch is cumulative, and includes fixes provided in the ArcGIS Server Security 2025 update 1.

      2026-05-22 10:58 UTC
    • web:cisa.gov

      Update (08/12/2025): CISA has updated this alert to provide clarification on identifying Exchange Servers on an organization's networks and provided further guidance on running the Microsoft Exchange Health Checker. Update (08/07/2025): CISA issued Emergency Directive (ED) 25-02: Mitigate Microsoft Exchange Vulnerability in response to CVE -2025-53786

      2026-05-22 10:58 UTC
    • web:support.servicenow.com

      This document lists all the released Store applications and schema changes for Vulnerability Response and Configuration Compliance. Vulnerability Response and Configuration Compliance Compatibility Matrix

      2026-05-22 03:00 UTC
    • web:blog.qualys.com

      See how you compare against enterprise patch and remediation , including patch deployment trends, automation adoption, and average remediation timelines.

      2026-05-22 03:00 UTC
    • web:portal.msrc.microsoft.com

      The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

      2026-05-22 03:00 UTC
    • web:source.android.com

      This Section contains the available Android Security Bulletins, which provide fixes for possible issues affecting Android devices.

      2026-05-22 03:00 UTC
    • web:support.google.com

      Google system services updates make your Android devices more secure and reliable, and give you new and useful features. They include updates from Google to the Android operating system, Google Play Store, and Google Play services. Google system services updates are available for phones, tablets, Android TV and Google TV devices, Android Auto-enabled devices, cars with Android Automotive OS or ...

      2026-05-22 03:00 UTC
    • web:access.redhat.com

      Learn about our open source products, services, and company. You are here

      2026-05-22 03:00 UTC
    • web:www.oracle.com

      This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.

      2026-05-22 03:00 UTC
    • web:www.tenable.com

      Mitigation Summary - Vulnerabilities by CVE ID: This matrix presents vulnerability summary information by Common Vulnerabilities and Exposures ( CVE ) identifier. The CVE system is a dictionary of publicly known information security vulnerabilities and exposures in publicly released software packages.

      2026-05-22 03:00 UTC
    • web:www.virustotal.com

      Streamline your investigations with Google Threat Intelligence Agentic and the new Dark Web (DDW) module. Perform hunting and pivoting across forums using natural language or specific modifiers. Bridge threat actor identities and map global operations easy.

      2026-05-22 03:00 UTC
    • web:www.windowslatest.com

      Windows 11 April 2026 update adds Narrator Copilot support, faster Settings, File Explorer fixes, and key security improvements.

      2026-05-22 03:00 UTC

    AI Forensic Analysis

    Only Available for Registered Users. Sign in to view.

    Raw JSON

    The full cvelistV5 record. Download as CVE-2024-55986.json.

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-55986",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-12-16T19:35:09.232271Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-12-16T19:44:04.354Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "packageName": "service",
              "product": "Service",
              "vendor": "tiny13",
              "versions": [
                {
                  "lessThanOrEqual": "1.0.4",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Mika | Patchstack Bug Bounty Program"
            }
          ],
          "datePublic": "2026-04-01T16:30:49.915Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tiny13 Service service allows Blind SQL Injection.<p>This issue affects Service: from n/a through <= 1.0.4.</p>"
                }
              ],
              "value": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tiny13 Service service allows Blind SQL Injection.This issue affects Service: from n/a through <= 1.0.4."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-7",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Blind SQL Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 8.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-04-28T16:10:53.382Z",
            "orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
            "shortName": "Patchstack"
          },
          "references": [
            {
              "tags": [
                "vdb-entry"
              ],
              "url": "https://patchstack.com/database/Wordpress/Plugin/service/vulnerability/wordpress-service-plugin-1-0-4-sql-injection-vulnerability?_s_id=cve"
            }
          ],
          "title": "WordPress Service plugin <= 1.0.4 - SQL Injection vulnerability"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
        "assignerShortName": "Patchstack",
        "cveId": "CVE-2024-55986",
        "datePublished": "2024-12-16T14:31:17.495Z",
        "dateReserved": "2024-12-14T19:41:53.296Z",
        "dateUpdated": "2026-04-28T16:10:53.382Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }