CVE-2021-26754: SQL Injection
Published Feb 7, 2021
·Updated
wpDataTables before 3.4.1 mishandles order direction for server-side tables, aka admin-ajax.php?action=getwdtable order[0][dir] SQL injection.
Affected Software
1 affected component
wpDataTables Wpdatatables Wordpress<3.4.1
Event History
Feb 7, 2021
CVE Published
via MITRE·11:31 PM
Data Sourced
via MITRE·11:31 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-26754?
CVE-2021-26754 is classified as a high severity vulnerability due to its potential for SQL injection exploitation.
2
How do I fix CVE-2021-26754?
To fix CVE-2021-26754, you should upgrade wpDataTables to version 3.4.1 or later.
3
Which versions of wpDataTables are affected by CVE-2021-26754?
CVE-2021-26754 affects all versions of wpDataTables prior to 3.4.1.
4
What type of vulnerability is CVE-2021-26754?
CVE-2021-26754 is an SQL injection vulnerability that occurs due to improper handling of order direction in server-side tables.
5
Can CVE-2021-26754 be exploited remotely?
Yes, CVE-2021-26754 can be exploited remotely if an attacker has access to the vulnerable wpDataTables plugin.