CVE-2021-24754
The MainWP Child Reports WordPress plugin before 2.0.8 does not validate or sanitise the order parameter before using it in a SQL statement in the admin dashboard, leading to an SQL injection issue
Source: CVE.org
CVE · High
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2021-24754 | MainWP Child Reports [mainwp-child-reports] < 2.0.8 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 7.2 | < 2.0.8 | 2.0.8 | 2021-09-20 | — |
The MainWP Child Reports WordPress plugin before 2.0.8 does not validate or sanitise the order parameter before using it in a SQL statement in the admin dashboard, leading to an SQL injection issue
Source: CVE.org
No signup, no credit card — enter your URL and get a security report in seconds.