CVE-2021-24506: Slider Hero < 8.2.7 - Contributor+ SQL Injection
The Slider Hero with Animation, Video Background & Intro Maker WordPress plugin before 8.2.7 does not sanitise or escape the id attribute of its hero-button shortcode before using it in a SQL statement, allowing users with a role as low as Contributor to perform SQL injection.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-24506.
What is the severity of CVE-2021-24506?
The severity of CVE-2021-24506 is high with a severity value of 8.8.
What does the Slider Hero with Animation WordPress plugin vulnerability allow?
The Slider Hero with Animation WordPress plugin vulnerability allows users with a role as low as Contributor to perform SQL injection.
Which version of the Slider Hero with Animation WordPress plugin is affected by CVE-2021-24506?
The Slider Hero with Animation WordPress plugin version up to and exclusive 8.2.7 is affected by CVE-2021-24506.
How can I fix the CVE-2021-24506 vulnerability?
To fix the CVE-2021-24506 vulnerability, update the Slider Hero with Animation WordPress plugin to version 8.2.7 or later.