CVE-2024-36082: Codepeople Music Store

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

SQL injection vulnerability in Music Store - WordPress eCommerce versions prior to 1.1.14 allows a remote authenticated attacker with an administrative privilege to execute arbitrary SQL commands. Information stored in the database may be obtained or altered by the attacker.

Affected products

  • Codepeople Music Store: before 1.1.14 (fixed in 1.1.14)

Published 2024-06-07. Last modified 2026-06-17.