CVE-2021-24774: Check & Log Email < 1.0.3 - Admin+ SQL Injections
The Check & Log Email WordPress plugin before 1.0.3 does not validate and escape the "order" and "orderby" GET parameters before using them in a SQL statement when viewing logs, leading to SQL injections issues
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24774?
CVE-2021-24774 is a vulnerability in the Check & Log Email WordPress plugin before version 1.0.3 that allows SQL injection attacks.
How does CVE-2021-24774 affect the Check & Log Email plugin?
CVE-2021-24774 allows an attacker to inject malicious SQL statements in the 'order' and 'orderby' GET parameters of the plugin's log viewing feature.
What is the severity of CVE-2021-24774?
CVE-2021-24774 has a severity rating of 7.2, which is considered high.
How can I fix CVE-2021-24774?
To fix CVE-2021-24774, update the Check & Log Email plugin to version 1.0.3 or later.
Is there any additional information about CVE-2021-24774?
Yes, you can find more information about CVE-2021-24774 at the following reference: [link](https://wpscan.com/vulnerability/f80ef09a-d3e2-4d62-8532-f0ebe59ae110)