First published: Mon Aug 02 2021(Updated: )
The get_sliders() function in the Image Slider by Ays- Responsive Slider and Carousel WordPress plugin before 2.5.0 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ays-pro Image Slider | <2.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-24463.
CVE-2021-24463 has a severity rating of 8.8.
The affected software for CVE-2021-24463 is the Image Slider by Ays- Responsive Slider and Carousel WordPress plugin before version 2.5.0.
CVE-2021-24463 is a SQL injection vulnerability in the get_sliders() function of the Image Slider by Ays- Responsive Slider and Carousel WordPress plugin before version 2.5.0.
To fix CVE-2021-24463, it is recommended to update the Image Slider by Ays- Responsive Slider and Carousel WordPress plugin to version 2.5.0 or newer.