Vulnerability Description
The Giveaway WordPress plugin through 1.2.2 is vulnerable to an SQL Injection issue which allows an administrative user to execute arbitrary SQL commands via the $post_id on the options.php page.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Satollo | Giveaway | <= 1.2.2 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/a1cf08fe-943a-4f14-beb0-25216011b538ExploitThird Party Advisory
- https://wpscan.com/vulnerability/a1cf08fe-943a-4f14-beb0-25216011b538ExploitThird Party Advisory
FAQ
What is CVE-2021-24497?
CVE-2021-24497 is a vulnerability with a CVSS score of 7.2 (HIGH). The Giveaway WordPress plugin through 1.2.2 is vulnerable to an SQL Injection issue which allows an administrative user to execute arbitrary SQL commands via the $post_id on the options.php page.
How severe is CVE-2021-24497?
CVE-2021-24497 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24497?
Check the references section above for vendor advisories and patch information. Affected products include: Satollo Giveaway.