CVE-2021-24769: Permalink Manager Lite < 2.2.13.1 - Admin+ SQL Injection
Published Oct 25, 2021
·Updated
The Permalink Manager Lite WordPress plugin before 2.2.13.1 does not validate and escape the orderby parameter before using it in a SQL statement in the Permalink Manager page, leading to a SQL Injection
Affected Software
1 affected component
Permalink Manager Lite Project Permalink Manager Lite Wordpress<2.2.13.1
Event History
Oct 25, 2021
CVE Published
via MITRE·01:20 PM
Data Sourced
via MITRE·01:20 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2021-24769.
2
What is the title of this vulnerability?
The title of this vulnerability is 'The Permalink Manager Lite WordPress plugin before 2.2.13.1 does not validate and escape the orderby...'
3
What is the affected software for this vulnerability?
The affected software is the Permalink Manager Lite WordPress plugin version up to 2.2.13.1.
4
What is the severity rating of this vulnerability?
The severity rating of this vulnerability is high (7.2).
5
How does this vulnerability work?
This vulnerability allows for SQL Injection by not validating and escaping the orderby parameter before using it in a SQL statement on the Permalink Manager page.