First published: Mon Aug 02 2021(Updated: )
The get_results() and get_items() functions in the Survey Maker WordPress plugin before 1.5.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ays-pro Survey Maker | <1.5.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24459 is a SQL injection vulnerability in the Survey Maker WordPress plugin before version 1.5.6.
CVE-2021-24459 allows for SQL injection attacks in the admin dashboard of the Survey Maker WordPress plugin.
CVE-2021-24459 has a severity rating of 8.8 (high).
To fix CVE-2021-24459, update the Survey Maker WordPress plugin to version 1.5.6 or later.
You can find more information about CVE-2021-24459 at the following reference: [link](https://wpscan.com/vulnerability/3fafbec0-55e4-41cf-8402-1b57b6615225).