CVE-2021-24858: WP Cookie User Info < 1.0.9 - Admin+ SQL Injection
Published Jan 24, 2022
·Updated
The Cookie Notification Plugin for WordPress plugin before 1.0.9 does not sanitise or escape the id GET parameter before using it in a SQL statement, when retrieving the setting to edit in the admin dashboard, leading to an authenticated SQL Injection
Affected Software
1 affected component
Accesspressthemes Wp Cookie User Info Wordpress<1.0.9
Event History
Jan 24, 2022
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-24858?
The severity of CVE-2021-24858 is high with a severity value of 7.2.
2
What does CVE-2021-24858 affect?
CVE-2021-24858 affects the Cookie Notification Plugin for WordPress plugin before version 1.0.9.
3
What is the vulnerability in CVE-2021-24858?
The vulnerability in CVE-2021-24858 is an authenticated SQL Injection.
4
How can CVE-2021-24858 be exploited?
CVE-2021-24858 can be exploited by manipulating the id GET parameter in a SQL statement.
5
Is there a fix available for CVE-2021-24858?
Yes, updating to version 1.0.9 of the Cookie Notification Plugin for WordPress plugin will fix CVE-2021-24858.