CVE · High

CVE-2021-24877 — MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 4.1.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24877 MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 4.1.8 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.2 < 4.1.8 4.1.8 2021-10-25

CVE-2021-24877

The MainWP Child plugin versions prior to 4.1.8 contain a SQL injection vulnerability in the orderby and order parameters that are passed directly into database queries without proper validation. This flaw can be exploited by administrators and other high-privilege users, particularly when the Backup and Staging by WP Time Capsule plugin is active on the site. The vulnerability allows attackers with elevated permissions to execute arbitrary SQL commands against the database.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.