CVE-2021-24666: Podlove Podcast Publisher < 3.5.6 - Unauthenticated SQL Injection
The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by default), which adds the rest route '/services/contributor/(?P<id>[\d]+), takes an 'id' and 'category' parameters as arguments. Both parameters can be used for the SQLi.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24666?
CVE-2021-24666 has a medium severity rating due to improper input validation in the Podlove Podcast Publisher plugin.
How do I fix CVE-2021-24666?
To fix CVE-2021-24666, update the Podlove Podcast Publisher plugin to version 3.5.6 or higher.
What are the affected versions for CVE-2021-24666?
The affected versions for CVE-2021-24666 are all versions of the Podlove Podcast Publisher plugin before 3.5.6.
What vulnerabilities are associated with CVE-2021-24666?
CVE-2021-24666 is associated with SQL injection vulnerabilities due to the misuse of parameters in the REST API.
Is the 'Social & Donations' module active by default in CVE-2021-24666?
No, the 'Social & Donations' module in the Podlove Podcast Publisher is not activated by default.