First published: Mon Jun 21 2021(Updated: )
In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sanitise or validate some of its POST parameters, which are then used in a SQL statement, leading to unauthenticated SQL Injection issues.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ayecode Location Manager | <2.1.0.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2021-24361.
CVE-2021-24361 has a severity rating of 9.8 (critical).
The affected software of CVE-2021-24361 is the Location Manager WordPress plugin before version 2.1.0.10.
The CWE category of this vulnerability is CWE-89 (SQL Injection).
To fix CVE-2021-24361, update the Location Manager WordPress plugin to version 2.1.0.10 or later.