Vulnerability Description
The Availability Calendar WordPress plugin before 1.2.1 does not escape the category attribute from its shortcode before using it in a SQL statement, leading to a SQL Injection issue, which can be exploited by any user able to add shortcode to posts/pages, such as contributor+
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Offshorewebmaster | Availability Calendar | < 1.2.1 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/fe49f48a-f97a-44fe-8d71-be08e7ce4f83ExploitThird Party Advisory
- https://wpscan.com/vulnerability/fe49f48a-f97a-44fe-8d71-be08e7ce4f83ExploitThird Party Advisory
FAQ
What is CVE-2021-24606?
CVE-2021-24606 is a vulnerability with a CVSS score of 8.8 (HIGH). The Availability Calendar WordPress plugin before 1.2.1 does not escape the category attribute from its shortcode before using it in a SQL statement, leading to a SQL Injection issue, which can be exp...
How severe is CVE-2021-24606?
CVE-2021-24606 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24606?
Check the references section above for vendor advisories and patch information. Affected products include: Offshorewebmaster Availability Calendar.