First published: Mon Oct 18 2021(Updated: )
The MainWP Child Reports WordPress plugin before 2.0.8 does not validate or sanitise the order parameter before using it in a SQL statement in the admin dashboard, leading to an SQL injection issue
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
MainWP MainWP Child Reports | <2.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24754 is a SQL injection vulnerability in the MainWP Child Reports WordPress plugin before version 2.0.8.
The severity of CVE-2021-24754 is high, with a CVSS score of 7.2.
CVE-2021-24754 allows an attacker to execute unauthorized SQL queries in the MainWP Child Reports plugin's admin dashboard.
To fix CVE-2021-24754, update the MainWP Child Reports plugin to version 2.0.8 or later.
Yes, you can find more information about CVE-2021-24754 at this link: https://wpscan.com/vulnerability/132118aa-4b72-4eaa-8aa1-6ad7b0c7f495