CVE-2021-24865: Advanced Custom Fields: Extended < 0.8.8.7 - Admin+ SQL Injection
The Advanced Custom Fields: Extended WordPress plugin before 0.8.8.7 does not validate the order and orderby parameters before using them in a SQL statement, leading to a SQL Injection issue
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24865?
CVE-2021-24865 is classified as a critical vulnerability due to its potential for SQL Injection, which can lead to unauthorized access to sensitive data.
How do I fix CVE-2021-24865?
To fix CVE-2021-24865, update the Advanced Custom Fields: Extended plugin to version 0.8.8.7 or later.
What are the implications of exploiting CVE-2021-24865?
Exploiting CVE-2021-24865 could allow attackers to execute arbitrary SQL queries, manipulate the database, and retrieve sensitive information.
Which versions are affected by CVE-2021-24865?
CVE-2021-24865 affects all versions of the Advanced Custom Fields: Extended plugin prior to 0.8.8.7.
Who should be concerned about CVE-2021-24865?
Anyone using the vulnerable versions of the Advanced Custom Fields: Extended plugin on WordPress sites should be concerned about CVE-2021-24865.