CVE-2021-24754: MainWP Child Reports < 2.0.8 - Admin+ SQL Injection
Published Oct 18, 2021
·Updated
The MainWP Child Reports WordPress plugin before 2.0.8 does not validate or sanitise the order parameter before using it in a SQL statement in the admin dashboard, leading to an SQL injection issue
Affected Software
1 affected component
MainWP MainWP Child Reports WordPress<2.0.8
Event History
Oct 18, 2021
CVE Published
via MITRE·01:46 PM
Data Sourced
via MITRE·01:46 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-24754?
CVE-2021-24754 is a SQL injection vulnerability in the MainWP Child Reports WordPress plugin before version 2.0.8.
2
What is the severity of CVE-2021-24754?
The severity of CVE-2021-24754 is high, with a CVSS score of 7.2.
3
How does CVE-2021-24754 affect the MainWP Child Reports plugin?
CVE-2021-24754 allows an attacker to execute unauthorized SQL queries in the MainWP Child Reports plugin's admin dashboard.
4
How can I fix CVE-2021-24754?
To fix CVE-2021-24754, update the MainWP Child Reports plugin to version 2.0.8 or later.
5
Is there any reference for CVE-2021-24754?
Yes, you can find more information about CVE-2021-24754 at this link: https://wpscan.com/vulnerability/132118aa-4b72-4eaa-8aa1-6ad7b0c7f495