890
VMScore

CVE-2021-26754

Published: 08/02/2021 Updated: 09/02/2021
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

wpDataTables prior to 3.4.1 mishandles order direction for server-side tables, aka admin-ajax.php?action=get_wdtable order[0][dir] SQL injection.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wpdatatables wpdatatables