6.5
CVSSv2

CVE-2021-24786

Published: 03/01/2022 Updated: 11/01/2022
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 580
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

The Download Monitor WordPress plugin prior to 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wpchill download monitor

Exploits

WordPress Download Monitor WordPress plugin versions prior to 445 suffer from a remote SQL injection vulnerability ...