Lucene search

K
cvelistWPScanCVELIST:CVE-2021-24521
HistoryAug 09, 2021 - 10:04 a.m.

CVE-2021-24521 Side Menu Lite < 2.2.1 - Authenticated SQL Injection

2021-08-0910:04:14
CWE-89
WPScan
www.cve.org
4
cve-2021-24521
side menu lite
authenticated sql injection
wordpress plugin
sql injection attack
administrator role

AI Score

7.6

Confidence

High

EPSS

0.001

Percentile

49.8%

The Side Menu Lite – add sticky fixed buttons WordPress plugin before 2.2.1 does not properly sanitize input values from the browser when building an SQL statement. Users with the administrator role or permission to manage this plugin could perform an SQL Injection attack.

CNA Affected

[
  {
    "product": "Side Menu Lite – add sticky fixed buttons",
    "vendor": "Unknown",
    "versions": [
      {
        "lessThan": "2.2.1",
        "status": "affected",
        "version": "2.2.1",
        "versionType": "custom"
      }
    ]
  }
]

AI Score

7.6

Confidence

High

EPSS

0.001

Percentile

49.8%

Related for CVELIST:CVE-2021-24521