CVE-2021-24755: myCred < 2.3 - Subscriber+ SQL Injection
Published Nov 29, 2021
·Updated
The myCred WordPress plugin before 2.3 does not validate or escape the fields parameter before using it in a SQL statement, leading to an SQL injection exploitable by any authenticated user
Affected Software
2 affected components
Mycred myCred WordPress<2.3
Wpexperts Mycred Wordpress<2.3
Event History
Nov 29, 2021
CVE Published
via MITRE·08:25 AM
Data Sourced
via MITRE·08:25 AM
DescriptionWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-24755.
2
What is the severity of CVE-2021-24755?
The severity of CVE-2021-24755 is high with a CVSS score of 8.8.
3
What is the affected software of CVE-2021-24755?
The affected software of CVE-2021-24755 is the myCred WordPress plugin before version 2.3.
4
What is the impact of CVE-2021-24755?
CVE-2021-24755 allows an authenticated user to exploit an SQL injection vulnerability in the myCred WordPress plugin.
5
How can I fix CVE-2021-24755?
To fix CVE-2021-24755, update the myCred WordPress plugin to version 2.3 or later.