First published: Thu Mar 18 2021(Updated: )
Unvaludated input in the 301 Redirects - Easy Redirect Manager WordPress plugin, versions before 2.51, did not sanitise its "Redirect From" column when importing a CSV file, allowing high privilege users to perform SQL injections.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Webfactoryltd 301 Redirects | <2.51 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24142 is considered a high severity vulnerability due to the potential for SQL injection by high privilege users.
To fix CVE-2021-24142, update the 301 Redirects - Easy Redirect Manager WordPress plugin to version 2.51 or later.
Users of the 301 Redirects - Easy Redirect Manager WordPress plugin versions prior to 2.51 are affected by CVE-2021-24142.
CVE-2021-24142 is a SQL injection vulnerability caused by unvalidated input when importing a CSV file.
The implications of CVE-2021-24142 include unauthorized access to the database and potential manipulation of data by high privilege users.