CVE-2021-24866: WP Data Access < 5.0.0 - Admin+ SQL Injection
Published Dec 6, 2021
·Updated
The WP Data Access WordPress plugin before 5.0.0 does not properly sanitise and escape the backupdate parameter before using it a SQL statement, leading to a SQL injection issue and could allow arbitrary table deletion
Affected Software
1 affected component
Wpdataaccess Wp Data Access Wordpress<5.0.0
Event History
Dec 6, 2021
CVE Published
via MITRE·03:55 PM
Data Sourced
via MITRE·03:55 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-24866?
CVE-2021-24866 has a medium severity rating due to the risk of SQL injection that could lead to arbitrary table deletion.
2
How do I fix CVE-2021-24866?
To fix CVE-2021-24866, you should update the WP Data Access plugin to version 5.0.0 or later.
3
What is the impact of CVE-2021-24866?
The impact of CVE-2021-24866 includes the potential for attackers to execute SQL injection attacks, resulting in unauthorized data deletion.
4
Is CVE-2021-24866 a defect in all versions of WP Data Access?
CVE-2021-24866 affects all versions of WP Data Access prior to 5.0.0.
5
What platforms are affected by CVE-2021-24866?
CVE-2021-24866 affects the WP Data Access plugin used on WordPress sites.