6
CVSSv2

CVE-2021-24877

Published: 23/11/2021 Updated: 26/11/2021
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

The MainWP Child WordPress plugin prior to 4.1.8 does not validate the orderby and order parameter before using them in a SQL statement, leading to an SQL injection exploitable by high privilege users such as admin when the Backup and Staging by WP Time Capsule plugin is installed

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mainwp mainwp child