CVE-2024-9201: Seur

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The SEUR plugin, in its versions prior to 2.5.11, is vulnerable to time-based SQL injection through the use of the ‘id_order’ parameter of the ‘/modules/seur/ajax/saveCodFee.php’ endpoint.

Affected products

  • Seur Seur: before 2.5.11 (fixed in 2.5.11)

Published 2024-10-10. Last modified 2026-06-17.