CVE-2021-24131: Anti-Spam by CleanTalk < 5.149 - Multiple Authenticated SQL Injections
Published Mar 18, 2021
·Updated
Unvalidated input in the Anti-Spam by CleanTalk WordPress plugin, versions before 5.149, lead to multiple authenticated SQL injection vulnerabilities, however, it requires high privilege user (admin+).
Affected Software
1 affected component
CleanTalk Anti-spam Wordpress<5.149
Event History
Mar 18, 2021
CVE Published
via MITRE·02:57 PM
Data Sourced
via MITRE·02:57 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-24131?
CVE-2021-24131 is a vulnerability in the Anti-Spam by CleanTalk WordPress plugin versions before 5.149 that leads to multiple authenticated SQL injection vulnerabilities.
2
What is the severity of CVE-2021-24131?
The severity of CVE-2021-24131 is high with a CVSS score of 7.2.
3
Which software versions are affected by CVE-2021-24131?
The Anti-Spam by CleanTalk WordPress plugin versions before 5.149 are affected by CVE-2021-24131.
4
What is the CWE ID of CVE-2021-24131?
CVE-2021-24131 is associated with CWE ID 89, which is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection').
5
Is CVE-2021-24131 exploitable by low-privileged users?
No, CVE-2021-24131 requires high privilege user (admin+) to be exploitable.