Collapsing Categories plugin for WordPress <= 3.0.8 contains a sql_injection caused by insufficient escaping of 'taxonomy' parameter in /wp-json/collapsing-categories/v1/get REST API, letting unauthenticated attackers execute arbitrary SQL queries, exploit requires sending crafted 'taxonomy' parameter.
id: CVE-2024-12025
info:
name: WordPress Collapsing Categories <= 3.0.8 - SQL Injection
author:
...