CVE-2021-24726
PoC ×2—CVSS 3.1
8.8 high
EPSS
2%p74
Published
()
Modified
Description
The WP Simple Booking Calendar WordPress plugin before 2.0.6 did not escape, validate or sanitise the orderby parameter in its Search Calendars action, before using it in a SQL statement, leading to an authenticated SQL injection issue
- Vendors
- wpsimplebookingcalendar
- Products
- wp simple booking calendar
- Ecosystems
- WordPress
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.