CVE-2021-25064: Wow Countdowns <= 3.1.2 - Admin+ SQLi
The Wow Countdowns WordPress plugin through 3.1.2 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authenticated SQL Injection.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-25064?
CVE-2021-25064 is a vulnerability in the Wow Countdowns WordPress plugin that allows for authenticated SQL Injection.
How severe is CVE-2021-25064?
CVE-2021-25064 has a severity rating of 7.2 (high).
What is the affected software for CVE-2021-25064?
The affected software for CVE-2021-25064 is the Wow Countdowns WordPress plugin version up to 3.1.2.
How does CVE-2021-25064 exploit the vulnerability?
CVE-2021-25064 exploits the vulnerability by not sanitizing user input into the 'did' parameter and using it in an SQL statement.
Is there a fix available for CVE-2021-25064?
At the moment, there is no specific fix available for CVE-2021-25064. It is recommended to update to the latest version of the Wow Countdowns WordPress plugin when a fix is released.