CVE Database /
CVE-2021-24877
CVE · High
CVE-2021-24877 — MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 4.1.8
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24877
|
MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 4.1.8 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
High
7.2
|
< 4.1.8
|
4.1.8 |
2021-10-25 |
—
|
CVE-2021-24877
The MainWP Child plugin versions prior to 4.1.8 contain a SQL injection vulnerability in the orderby and order parameters that are passed directly into database queries without proper validation. This flaw can be exploited by administrators and other high-privilege users, particularly when the Backup and Staging by WP Time Capsule plugin is active on the site. The vulnerability allows attackers with elevated permissions to execute arbitrary SQL commands against the database.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings