CVE-2021-24748

The Email Before Download WordPress plugin before 6.8 does not properly validate and escape the order and orderby GET parameters before using them in SQL statements, leading to authenticated SQL injection issues
Configurations

Configuration 1 (hide)

cpe:2.3:a:mandsconsulting:email_before_download:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2021-11-29 09:15

Updated : 2024-11-21 05:53


NVD link : CVE-2021-24748

Mitre link : CVE-2021-24748

CVE.ORG link : CVE-2021-24748


JSON object : View

Products Affected

mandsconsulting

  • email_before_download
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')