CVE-2021-24199: wpDataTables < 3.4.2 - Blind SQL Injection via start Parameter
The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user to perform Boolean-based blind SQL Injection in the table list page on the endpoint /wp-admin/admin-ajax.php?action=getwdtable&tableid=1, on the 'start' HTTP POST parameter. This allows an attacker to access all the data in the database and obtain access to the WordPress application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24199?
CVE-2021-24199 is classified as a critical vulnerability due to its ability to allow a low privilege authenticated user to perform SQL injection attacks.
How do I fix CVE-2021-24199?
To fix CVE-2021-24199, update the wpDataTables plugin to version 3.4.2 or later.
What type of vulnerability is CVE-2021-24199?
CVE-2021-24199 is a Boolean-based blind SQL Injection vulnerability.
Which software is affected by CVE-2021-24199?
CVE-2021-24199 affects the wpDataTables plugin for WordPress versions before 3.4.2.
Can CVE-2021-24199 be exploited by unauthenticated users?
No, CVE-2021-24199 requires a low privilege authenticated user to exploit the vulnerability.