Vulnerability Description
The Slider Hero with Animation, Video Background & Intro Maker WordPress plugin before 8.2.7 does not sanitise or escape the id attribute of its hero-button shortcode before using it in a SQL statement, allowing users with a role as low as Contributor to perform SQL injection.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Quantumcloud | Slider Hero | < 8.2.7 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/52c8755c-46b9-4383-8c8d-8816f03456b0ExploitThird Party Advisory
- https://wpscan.com/vulnerability/52c8755c-46b9-4383-8c8d-8816f03456b0ExploitThird Party Advisory
FAQ
What is CVE-2021-24506?
CVE-2021-24506 is a vulnerability with a CVSS score of 8.8 (HIGH). The Slider Hero with Animation, Video Background & Intro Maker WordPress plugin before 8.2.7 does not sanitise or escape the id attribute of its hero-button shortcode before using it in a SQL statemen...
How severe is CVE-2021-24506?
CVE-2021-24506 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24506?
Check the references section above for vendor advisories and patch information. Affected products include: Quantumcloud Slider Hero.