{"id":"CVE-2024-27956","aliases":[],"url":"https://o3.security/vulnerability/CVE-2024-27956","summary":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0.","details":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0.","published":"2024-03-21T17:15:08.437","modified":"2026-06-17T07:20:40.200","cvss":{"score":9.9,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L"},"epss":{"score":0.93971,"percentile":0.99837,"asOf":"2026-08-27"},"cisaKev":null,"exploitsKnown":9,"affectedPackages":[],"fix":null,"references":[{"type":"ADVISORY","url":"https://patchstack.com/articles/critical-vulnerabilities-patched-in-wordpress-automatic-plugin?_s_id=cve"},{"type":"ADVISORY","url":"https://patchstack.com/database/vulnerability/wp-automatic/wordpress-automatic-plugin-3-92-0-unauthenticated-arbitrary-sql-execution-vulnerability?_s_id=cve"},{"type":"ADVISORY","url":"https://patchstack.com/articles/critical-vulnerabilities-patched-in-wordpress-automatic-plugin?_s_id=cve"},{"type":"ADVISORY","url":"https://patchstack.com/database/vulnerability/wp-automatic/wordpress-automatic-plugin-3-92-0-unauthenticated-arbitrary-sql-execution-vulnerability?_s_id=cve"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T07:20:40.200"}}