Vulnerability Description
The Email Before Download WordPress plugin before 6.8 does not properly validate and escape the order and orderby GET parameters before using them in SQL statements, leading to authenticated SQL injection issues
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mandsconsulting | Email Before Download | < 6.8 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/a8625b84-337d-4c4d-a698-73e59d1f8ee1ExploitThird Party Advisory
- https://wpscan.com/vulnerability/a8625b84-337d-4c4d-a698-73e59d1f8ee1ExploitThird Party Advisory
FAQ
What is CVE-2021-24748?
CVE-2021-24748 is a vulnerability with a CVSS score of 8.8 (HIGH). The Email Before Download WordPress plugin before 6.8 does not properly validate and escape the order and orderby GET parameters before using them in SQL statements, leading to authenticated SQL injec...
How severe is CVE-2021-24748?
CVE-2021-24748 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24748?
Check the references section above for vendor advisories and patch information. Affected products include: Mandsconsulting Email Before Download.