7.2
CVSSv3

CVE-2021-24629

Published: 08/11/2021 Updated: 10/11/2021
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

The Post Content XMLRPC WordPress plugin up to and including 1.0 does not sanitise or escape multiple GET/POST parameters before using them in SQL statements in the admin dashboard, leading to an authenticated SQL Injections

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

post content xmlrpc project post content xmlrpc