CVE-2024-47304
📛 CVE Title
WordPress Fluent Support plugin <= 1.8.0 - SQL Injection vulnerability
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Fluent Support fluent-support allows SQL Injection.This issue affects Fluent Support: from n/a through <= 1.8.0.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- Patchstack
- CVSS severity
- HIGH
- CVSS score
- 8.5 / 10
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L- Effective score
- 8.5 / 10 HIGH source: CNA overview
- CWE(s)
-
CWE-89 - Reserved
- 2024-09-24
- Published
- 2024-10-17 19:36 UTC
- Last updated
- 2026-04-28 18:10 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/47xxx/CVE-2024-47304.json
- Linked Threat
- CVE-2024-47304 — Fluent Support <= 1.8.0 - Authenticated (Subscriber+) SQL Injection
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2024-10-17 18:15:07 UTC
- NVD last modified
- 2026-06-17 07:56:50 UTC
- NVD CVSS v3.1
- 8.5 / 10 HIGH source: audit@patchstack.com
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L- Exploitability subscore
- 3.1 / 10
- Impact subscore
- 4.7 / 10
- EPSS score
- 0.0041 (probability of exploitation in next 30 days)
- EPSS percentile
- 32.53% vs all CVEs — higher = more likely to be exploited, as of 2026-06-30
NVD / KEV / EPSS data refreshed 2026-06-30 20:48 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2024-42340 - Assigner
- Patchstack
- Published
- Oct 17, 2024, 5:36:26 PM
- Updated
- Apr 28, 2026, 4:10:18 PM
- EUVD base score (CVSS 3.1)
-
8.5 / 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L - EUVD-reported EPSS
- 0.3500
- Vendors
- Shahjahan Jewel, WPManageNinja LLC
- Products
-
Fluent Support (n/a ≤1.8.0)Fluent Support (0 ≤1.8.0)
- Aliases
-
GHSA-hjh2-x5x2-gfcq
ENISA description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Fluent Support fluent-support allows SQL Injection.This issue affects Fluent Support: from n/a through <= 1.8.0.
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Shahjahan Jewel | Fluent Support |
0 (affected)
|
— |
Affected products — CPE 2.3 (1) NVD
NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.
cpe:2.3:a:wpmanageninja:fluent_support:*:*:*:*:*:wordpress:*:*
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
MITRE references (1) cveawg.mitre.org
Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.
Web references (5)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- http://cwe.mitre.org/data/definitions/89.html rapid7:cwe.mitre.org
- https://attackerkb.com/topics/CVE-2024-47304 rapid7:attackerkb.com
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-42340 rapid7:euvd.enisa.europa.eu
- https://www.cve.org/CVERecord?id=CVE-2024-47304 rapid7:www.cve.org
- https://www.wordfence.com/threat-intel/vulnerabilities/id/b78985ad-37e5-4eb3-b3aa-716972423848?source=api-prod rapid7:www.wordfence.com
NVD-tagged references (1)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
Indicators (2)
IOCs linked to the auto-promoted Threat row.
| Type | Value | VirusTotal | Attached |
|---|---|---|---|
| domain |
injection.this
|
no local data | 2026-05-18 21:19 UTC |
| cve |
CVE-2024-47304
|
no local data | 2026-06-06 14:20 UTC |
Remediations (20)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:windowsforum.com
CVE -2026- 47304 , an Important-rated .NET security feature bypass, was fixed in Microsoft's July 14, 2026 security releases for .NET 8, .NET 9, .NET 10, .NET Framework, and supported Visual Studio editions. The flaw carries a CVSS 3.1 score of 8.1 and could let an unauthenticated remote attacker bypass cryptographic protections without user interaction. Microsoft describes the vulnerability as ...
2026-08-01 14:01 UTC -
web:app.opencve.io
Remediation No vendor fix or workaround currently provided. OpenCVE Recommended Actions Apply the Microsoft‑provided patch that corrects the signature verification logic in .NET and Visual Studio.
2026-08-01 14:01 UTC -
web:learn.microsoft.com
This update installs the complete .NET Framework 3.5 product for Windows 11, version 26H1 (build version 28000) and newer. Unlike traditional cumulative updates that patch individual components, this delivers the full .NET Framework 3.5 product as a standalone installer. It replaces any previously installed version.
2026-08-01 14:01 UTC -
web:linux.oracle.com
Oracle Linux CVE Details: CVE -2026- 47304 Description Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network. See more information about CVE -2026- 47304 from MITRE CVE dictionary and NIST NVD NOTE: The following CVSS metrics and score provided are preliminary and subject to review. CVSS v3 metrics
2026-08-01 14:01 UTC -
web:msrc.microsoft.com
The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.
2026-08-01 14:01 UTC -
web:www.rapid7.com
CVE -2026- 47304 : Improper Verification of Cryptographic Signature. View severity, references, and remediation details from Rapid7.
2026-08-01 14:01 UTC -
web:www.cve.org
Vulnerability detail for CVE-2024-47304 Notice: Expanded keyword searching of CVE Records (with limitations) is now available in the search box above. Learn more here.
2026-08-01 14:01 UTC -
Wordfence remediation: Fluent Support – Helpdesk & Customer Support Ticket SystemWordfence
Update to version 1.8.1, or a newer patched version
2026-06-06 14:20 UTC -
web:www.oracle.com
Oracle Critical Patch Update Advisory - October 2024 Description A Critical Patch Update is a collection of patches for multiple security vulnerabilities. These patches address vulnerabilities in Oracle code and in third party components included in Oracle products. These patches are usually cumulative, but each advisory describes only the security patches added since the previous Critical ...
2026-05-22 10:20 UTC -
web:www.cybersecuritydive.com
The Cybersecurity and Infrastructure Security Agency added two major software flaws to its Known Exploited Vulnerabilities (KEV) catalog on Tuesday, acknowledging the evidence that hackers have been using the bugs in recent attacks. CISA added CVE - 2024 -1708, a high-severity flaw in ConnectWise's ScreenConnect remote-access tool, and CVE -2026-32202, a medium-severity flaw in the Windows Shell ...
2026-05-22 10:20 UTC -
web:www.cisa.gov
. For more information see MAR-251132.c1.v1 Exploitation of SharePoint Vulnerabilities and CISA Releases Malware Analysis Report Associated with Microsoft SharePoint Vulnerabilities. Update (07/31/2025): CISA has updated this alert to provide clarification on antivirus and endpoint detection and response (EDR) solutions, and details regarding mitigations related to the IIS server. Update (07 ...
2026-05-22 02:52 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-22 02:52 UTC -
web:www.forbes.com
Microsoft starts expiring critical Secure Boot certificates in just 2 weeks.
2026-05-22 02:52 UTC -
web:www.ninjaone.com
Overview KB5087054 is a cumulative security and reliability update for the .NET Framework targeting Windows 11 version 24H2 systems. Released on May 12, 2026, this patch addresses critical vulnerabilities affecting both .NET Framework 3.5 and 4.8.1 installations. The update is designed to be deployed as part of standard maintenance routines and is available through multiple distribution ...
2026-05-22 02:52 UTC -
web:www.notebookcheck.net
Microsoft April 2026 Patch Tuesday fixes 167 vulnerabilities, including an actively exploited SharePoint zero-day. Windows 11 KB5083769 and KB5082052 bring new builds and RDP security.
2026-05-22 02:52 UTC -
web:nvd.nist.gov
An official website of the United States government Here's how you know
2026-05-22 02:52 UTC -
web:www.windowslatest.com
Windows 11 April 2026 update adds Narrator Copilot support, faster Settings, File Explorer fixes, and key security improvements.
2026-05-22 02:52 UTC -
web:thecyberexpress.com
Microsoft Patch Tuesday: Zero-Day Vulnerabilities in Focus A major focus of this Patch Tuesday April 2026 cycle is the remediation of two zero-day vulnerabilities. One of the most concerning issues is an actively exploited spoofing vulnerability in Microsoft SharePoint Server.
2026-05-22 02:52 UTC -
web:krebsonsecurity.com
Microsoft Corp. today issued security updates to fix more than 80 vulnerabilities in its Windows operating systems and software. There are no known "zero-day" or actively exploited vulnerabilities ...
2026-05-22 02:52 UTC -
web:redmondmag.com
Microsoft this week released one of the largest Patch Tuesday bundles in its history, delivering fixes for 163 new Microsoft CVEs in a month that includes three zero-days and eight Critical-rated ...
2026-05-22 02:52 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2024-47304.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-47304",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-10-17T19:30:42.803197Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-10-17T19:30:53.639Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://wordpress.org/plugins",
"defaultStatus": "unaffected",
"packageName": "fluent-support",
"product": "Fluent Support",
"vendor": "Shahjahan Jewel",
"versions": [
{
"changes": [
{
"at": "1.8.1",
"status": "unaffected"
}
],
"lessThanOrEqual": "1.8.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Abu Hurayra | Patchstack Bug Bounty Program"
}
],
"datePublic": "2026-04-01T16:27:43.737Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Fluent Support fluent-support allows SQL Injection.<p>This issue affects Fluent Support: from n/a through <= 1.8.0.</p>"
}
],
"value": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Fluent Support fluent-support allows SQL Injection.This issue affects Fluent Support: from n/a through <= 1.8.0."
}
],
"impacts": [
{
"capecId": "CAPEC-66",
"descriptions": [
{
"lang": "en",
"value": "SQL Injection"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 8.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-04-28T16:10:18.435Z",
"orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"shortName": "Patchstack"
},
"references": [
{
"tags": [
"vdb-entry"
],
"url": "https://patchstack.com/database/Wordpress/Plugin/fluent-support/vulnerability/wordpress-fluent-support-plugin-1-8-0-sql-injection-vulnerability?_s_id=cve"
}
],
"title": "WordPress Fluent Support plugin <= 1.8.0 - SQL Injection vulnerability"
}
},
"cveMetadata": {
"assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"assignerShortName": "Patchstack",
"cveId": "CVE-2024-47304",
"datePublished": "2024-10-17T17:36:26.988Z",
"dateReserved": "2024-09-24T13:00:11.340Z",
"dateUpdated": "2026-04-28T16:10:18.435Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}