CVE-2021-24137: Blog2Social: Social Media Auto Post & Scheduler < 6.3.1 - Authenticated SQL Injection
Unvalidated input in the Blog2Social WordPress plugin, versions before 6.3.1, lead to SQL Injection in the Re-Share Posts feature, allowing authenticated users to inject arbitrary SQL commands.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24137?
CVE-2021-24137 refers to an unvalidated input vulnerability in the Blog2Social WordPress plugin, versions before 6.3.1, that can lead to SQL Injection in the Re-Share Posts feature.
What is the severity of CVE-2021-24137?
The severity of CVE-2021-24137 is rated as high with a CVSS score of 8.8.
How does CVE-2021-24137 affect the Blog2Social WordPress plugin?
CVE-2021-24137 affects the Blog2Social WordPress plugin versions before 6.3.1 and allows authenticated users to inject arbitrary SQL commands through the Re-Share Posts feature.
How can I fix the CVE-2021-24137 vulnerability?
To fix the CVE-2021-24137 vulnerability, update the Blog2Social WordPress plugin to version 6.3.1 or later.
What is CWE-89?
CWE-89 is a common weakness enumeration referring to SQL Injection vulnerabilities.