Vulnerability Description
The MainWP Child WordPress plugin before 4.1.8 does not validate the orderby and order parameter before using them in a SQL statement, leading to an SQL injection exploitable by high privilege users such as admin when the Backup and Staging by WP Time Capsule plugin is installed
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mainwp | Mainwp Child | < 4.1.8 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/b09fe120-ab9b-44f2-b50d-3b4b299d6d15ExploitThird Party Advisory
- https://wpscan.com/vulnerability/b09fe120-ab9b-44f2-b50d-3b4b299d6d15ExploitThird Party Advisory
FAQ
What is CVE-2021-24877?
CVE-2021-24877 is a vulnerability with a CVSS score of 7.2 (HIGH). The MainWP Child WordPress plugin before 4.1.8 does not validate the orderby and order parameter before using them in a SQL statement, leading to an SQL injection exploitable by high privilege users s...
How severe is CVE-2021-24877?
CVE-2021-24877 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24877?
Check the references section above for vendor advisories and patch information. Affected products include: Mainwp Mainwp Child.