Vulnerability Description
The Futurio Extra WordPress plugin before 1.6.3 is affected by a SQL Injection vulnerability that could be used by high privilege users to extract data from the database as well as used to perform Cross-Site Scripting (XSS) against logged in admins by making send open a malicious link.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Futuriowp | Futurio Extra | < 1.6.3 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/36261af9-3b34-4563-af3c-c9e54ae2d581ExploitThird Party Advisory
- https://wpscan.com/vulnerability/36261af9-3b34-4563-af3c-c9e54ae2d581ExploitThird Party Advisory
FAQ
What is CVE-2021-25109?
CVE-2021-25109 is a vulnerability with a CVSS score of 2.7 (LOW). The Futurio Extra WordPress plugin before 1.6.3 is affected by a SQL Injection vulnerability that could be used by high privilege users to extract data from the database as well as used to perform Cro...
How severe is CVE-2021-25109?
CVE-2021-25109 has been rated LOW with a CVSS base score of 2.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-25109?
Check the references section above for vendor advisories and patch information. Affected products include: Futuriowp Futurio Extra.