CVE-2021-24484: Secure Copy Content Protection and Content Locking < 2.6.7 - Authenticated Blind SQL Injections
The getreports() function in the Secure Copy Content Protection and Content Locking WordPress plugin before 2.6.7 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the getresults() DB calls, leading to SQL injection issues in the admin dashboard
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-24484.
What is the severity of CVE-2021-24484?
CVE-2021-24484 has a severity of 7.2 (high).
What is the affected software?
The affected software is the Secure Copy Content Protection and Content Locking WordPress plugin before version 2.6.7.
What is the description of CVE-2021-24484?
CVE-2021-24484 is a SQL injection vulnerability in the get_reports() function of the Secure Copy Content Protection and Content Locking WordPress plugin.
How do I fix CVE-2021-24484?
To fix CVE-2021-24484, update the Secure Copy Content Protection and Content Locking WordPress plugin to version 2.6.7 or higher.