ZeroHour

CVE-2021-24456

CVSS 3.1
7.2 high
EPSS
1%p69
Published
()
Modified
Description

The Quiz Maker WordPress plugin before 6.2.0.9 did not properly sanitise and escape the order and orderby parameters before using them in SQL statements, leading to SQL injection issues in the admin dashboard

Vendors
ays-pro
Products
quiz maker
Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.