7.2
CVSSv3

CVE-2021-24348

Published: 14/06/2021 Updated: 07/11/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

The menu delete functionality of the Side Menu – add fixed side buttons WordPress plugin prior to 3.1.5, available to Administrator users takes the did GET parameter and uses it into an SQL statement without proper sanitisation, validation or escaping, therefore leading to a SQL Injection issue

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wow-estore side menu