CVE · High

CVE-2021-24848 — Mediamatic – Media Library Folders [mediamatic] < 2.8.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24848 Mediamatic – Media Library Folders [mediamatic] < 2.8.1 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.8 < 2.8.1 2.8.1 2021-11-15

CVE-2021-24848

The Mediamatic WordPress plugin before version 2.8.1 contains an SQL injection vulnerability in its mediamaticAjaxRenameCategory AJAX action. Any logged-in user can exploit this flaw by sending a malicious categoryID parameter that is not properly cleaned before being passed into a SQL query. This vulnerability allows authenticated attackers to execute arbitrary SQL commands against the database.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.