CVE-2021-24507: Astra Pro Addon < 3.5.2 - Unauthenticated SQL Injection
The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from the astrapaginationinfinite and astrashoppaginationinfinite AJAX action (available to both unauthenticated and authenticated user) before using them in SQL statement, leading to an SQL Injection issues
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24507?
The severity of CVE-2021-24507 is critical (9.8).
What is the affected software of CVE-2021-24507?
The affected software of CVE-2021-24507 is Brainstormforce Astra Pro Addon WordPress plugin version up to 3.5.2.
How does CVE-2021-24507 affect unauthenticated and authenticated users?
CVE-2021-24507 affects both unauthenticated and authenticated users of the Astra Pro Addon WordPress plugin before version 3.5.2.
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-24507?
The Common Weakness Enumeration (CWE) ID for CVE-2021-24507 is CWE-89.
How can I fix CVE-2021-24507?
To fix CVE-2021-24507, update the Astra Pro Addon WordPress plugin to version 3.5.2 or later.