Vulnerability Description
The Quiz Maker WordPress plugin before 6.2.0.9 did not properly sanitise and escape the order and orderby parameters before using them in SQL statements, leading to SQL injection issues in the admin dashboard
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ays-Pro | Quiz Maker | < 6.2.0.9 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/929ad37d-9cdb-4117-8cd3-cf7130a7c9d4Third Party Advisory
- https://wpscan.com/vulnerability/929ad37d-9cdb-4117-8cd3-cf7130a7c9d4Third Party Advisory
FAQ
What is CVE-2021-24456?
CVE-2021-24456 is a vulnerability with a CVSS score of 7.2 (HIGH). The Quiz Maker WordPress plugin before 6.2.0.9 did not properly sanitise and escape the order and orderby parameters before using them in SQL statements, leading to SQL injection issues in the admin d...
How severe is CVE-2021-24456?
CVE-2021-24456 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24456?
Check the references section above for vendor advisories and patch information. Affected products include: Ays-Pro Quiz Maker.