CVE-2021-4134: Fancy Product Designer <= 4.7.4 Admin+ SQL Injection
The Fancy Product Designer WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the ID parameter found in the ~/inc/api/class-view.php file which allows attackers with administrative level permissions to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 4.7.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-4134?
CVE-2021-4134 is a vulnerability in the Fancy Product Designer WordPress plugin that allows attackers with administrative level permissions to inject arbitrary SQL queries.
What is the severity of CVE-2021-4134?
The severity of CVE-2021-4134 is high with a severity score of 4.9.
How does CVE-2021-4134 affect the Fancy Product Designer WordPress plugin?
CVE-2021-4134 affects the Fancy Product Designer WordPress plugin by allowing attackers to perform SQL injection attacks through the ID parameter in the class-view.php file.
Which version of the Fancy Product Designer WordPress plugin is affected by CVE-2021-4134?
The Fancy Product Designer WordPress plugin version up to 4.7.5 is affected by CVE-2021-4134.
How can I fix CVE-2021-4134 vulnerability?
To fix the CVE-2021-4134 vulnerability, it is recommended to update the Fancy Product Designer WordPress plugin to a version higher than 4.7.5.