CVE Database /
CVE-2021-24877
CVE · High
CVE-2021-24877 — MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 4.1.8
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24877
|
MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites [mainwp-child] < 4.1.8 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
High
7.2
|
< 4.1.8
|
4.1.8 |
2021-10-25 |
—
|
CVE-2021-24877
The MainWP Child WordPress plugin before 4.1.8 does not validate the orderby and order parameter before using them in a SQL statement, leading to an SQL injection exploitable by high privilege users such as admin when the Backup and Staging by WP Time Capsule plugin is installed
Source:
CVE.org
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings