Vulnerability Description
The Advanced Custom Fields: Extended WordPress plugin before 0.8.8.7 does not validate the order and orderby parameters before using them in a SQL statement, leading to a SQL Injection issue
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Acf-Extended | Advanced Custom Fields\ | < 0.8.8.7, extended |
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/changeset/2648200PatchThird Party Advisory
- https://wpscan.com/vulnerability/055a2dcf-77ec-4e54-be7d-9c47f7730d1bExploitThird Party Advisory
- https://plugins.trac.wordpress.org/changeset/2648200PatchThird Party Advisory
- https://wpscan.com/vulnerability/055a2dcf-77ec-4e54-be7d-9c47f7730d1bExploitThird Party Advisory
FAQ
What is CVE-2021-24865?
CVE-2021-24865 is a vulnerability with a CVSS score of 7.2 (HIGH). The Advanced Custom Fields: Extended WordPress plugin before 0.8.8.7 does not validate the order and orderby parameters before using them in a SQL statement, leading to a SQL Injection issue
How severe is CVE-2021-24865?
CVE-2021-24865 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24865?
Check the references section above for vendor advisories and patch information. Affected products include: Acf-Extended Advanced Custom Fields\.