ZeroHour

CVE-2021-24726

PoC ×2
CVSS 3.1
8.8 high
EPSS
2%p74
Published
()
Modified
Description

The WP Simple Booking Calendar WordPress plugin before 2.0.6 did not escape, validate or sanitise the orderby parameter in its Search Calendars action, before using it in a SQL statement, leading to an authenticated SQL injection issue

Vendors
wpsimplebookingcalendar
Products
wp simple booking calendar
Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.