ZeroHour

CVE-2021-24629

PoC ×2
CVSS 3.1
7.2 high
EPSS
2%p74
Published
()
Modified
Description

The Post Content XMLRPC WordPress plugin through 1.0 does not sanitise or escape multiple GET/POST parameters before using them in SQL statements in the admin dashboard, leading to an authenticated SQL Injections

Vendors
post content xmlrpc project
Products
post content xmlrpc
Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.