ZeroHour

CVE-2021-24748

PoC
CVSS 3.1
8.8 high
EPSS
1%p69
Published
()
Modified
Description

The Email Before Download WordPress plugin before 6.8 does not properly validate and escape the order and orderby GET parameters before using them in SQL statements, leading to authenticated SQL injection issues

Vendors
mandsconsulting
Products
email before download
Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.