CVE · Critical

CVE-2021-24507 — Astra Pro Addon [astra-addon] < 3.5.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24507 Astra Pro Addon [astra-addon] < 3.5.2 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.8 < 3.5.2 3.5.2 2021-07-08

CVE-2021-24507

The Astra Pro Addon plugin before version 3.5.2 contains SQL injection vulnerabilities in its AJAX handlers for astra_pagination_infinite and astra_shop_pagination_infinite actions. These endpoints fail to properly sanitize POST parameters before inserting them into database queries, and are accessible to both logged-in and unauthenticated users. An attacker could exploit this flaw to execute arbitrary SQL commands and potentially access or manipulate sensitive database information.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.