First published: Mon Aug 02 2021(Updated: )
The get_ays_popupboxes() and get_popup_categories() functions of the Popup box WordPress plugin before 2.3.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ays-pro Popup Box | <2.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24458 is a vulnerability in the Popup box WordPress plugin before version 2.3.4 that allows SQL injection issues in the admin dashboard.
The vulnerability occurs because the get_ays_popupboxes() and get_popup_categories() functions of the Popup box WordPress plugin do not validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls.
CVE-2021-24458 has a severity rating of 8.8 (high).
The Popup box WordPress plugin before version 2.3.4 is affected by CVE-2021-24458.
To fix CVE-2021-24458, it is recommended to update the Popup box WordPress plugin to version 2.3.4 or later.