CVE-2021-24459: Survey Maker < 1.5.6 - Authenticated Blind SQL Injections
The getresults() and getitems() functions in the Survey Maker WordPress plugin before 1.5.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the getresults() DB calls, leading to SQL injection issues in the admin dashboard
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24459 vulnerability?
CVE-2021-24459 is a SQL injection vulnerability in the Survey Maker WordPress plugin before version 1.5.6.
How does CVE-2021-24459 affect the Survey Maker WordPress plugin?
CVE-2021-24459 allows for SQL injection attacks in the admin dashboard of the Survey Maker WordPress plugin.
What is the severity of CVE-2021-24459?
CVE-2021-24459 has a severity rating of 8.8 (high).
How can I fix CVE-2021-24459 vulnerability?
To fix CVE-2021-24459, update the Survey Maker WordPress plugin to version 1.5.6 or later.
Where can I find more information about CVE-2021-24459?
You can find more information about CVE-2021-24459 at the following reference: [link](https://wpscan.com/vulnerability/3fafbec0-55e4-41cf-8402-1b57b6615225).