First published: Mon Jan 10 2022(Updated: )
The WPcalc WordPress plugin through 2.1 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authenticated SQL Injection vulnerability.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wow-company Wpcalc | <=2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25054 is an authenticated SQL Injection vulnerability in the WPcalc WordPress plugin through version 2.1.
CVE-2021-25054 has a severity score of 8.8 out of 10.
CVE-2021-25054 allows an authenticated attacker to perform SQL injection attacks by exploiting the 'did' parameter in the plugin.
Yes, updating the WPcalc WordPress plugin to a version beyond 2.1 will fix the authenticated SQL Injection vulnerability (CVE-2021-25054).
You can find more information about CVE-2021-25054 at this [reference link](https://wpscan.com/vulnerability/200969eb-e2a4-4200-82d7-0c313de089af).