Vulnerability Description
The MOLIE WordPress plugin through 0.5 does not validate and escape a post parameter before using in a SQL statement, leading to an SQL Injection
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Molie Instructure Canvas Linking Tool Project | Molie Instructure Canvas Linking Tool | <= 0.5 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/cf907d53-cc4a-4b02-bed3-64754128112cExploitThird Party Advisory
- https://wpscan.com/vulnerability/cf907d53-cc4a-4b02-bed3-64754128112cExploitThird Party Advisory
FAQ
What is CVE-2021-25007?
CVE-2021-25007 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The MOLIE WordPress plugin through 0.5 does not validate and escape a post parameter before using in a SQL statement, leading to an SQL Injection
How severe is CVE-2021-25007?
CVE-2021-25007 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-25007?
Check the references section above for vendor advisories and patch information. Affected products include: Molie Instructure Canvas Linking Tool Project Molie Instructure Canvas Linking Tool.