First published: Mon Jan 24 2022(Updated: )
The Advanced Custom Fields: Extended WordPress plugin before 0.8.8.7 does not validate the order and orderby parameters before using them in a SQL statement, leading to a SQL Injection issue
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Advanced Custom Fields | <0.8.8.7 | |
Advanced Custom Fields | <0.8.8.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24865 is classified as a critical vulnerability due to its potential for SQL Injection, which can lead to unauthorized access to sensitive data.
To fix CVE-2021-24865, update the Advanced Custom Fields: Extended plugin to version 0.8.8.7 or later.
Exploiting CVE-2021-24865 could allow attackers to execute arbitrary SQL queries, manipulate the database, and retrieve sensitive information.
CVE-2021-24865 affects all versions of the Advanced Custom Fields: Extended plugin prior to 0.8.8.7.
Anyone using the vulnerable versions of the Advanced Custom Fields: Extended plugin on WordPress sites should be concerned about CVE-2021-24865.