First published: Mon Aug 30 2021(Updated: )
The Side Menu Lite WordPress plugin before 2.2.6 does not sanitise user input from the List page in the admin dashboard before using it in SQL statement, leading to a SQL Injection issue
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wow-estore Side Menu | <2.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-24580.
The severity of CVE-2021-24580 is high with a severity value of 8.8.
The Side Menu Lite WordPress plugin before 2.2.6 does not sanitise user input from the List page in the admin dashboard before using it in SQL statements, which can lead to a SQL Injection issue.
The affected software is the Wow-estore Side Menu plugin (Lite version) for WordPress up to version 2.2.6.
To fix CVE-2021-24580 in the Side Menu Lite WordPress plugin, update to version 2.2.6 or later which includes the necessary sanitization of user input.