Lucene search

K
cvelistWPScanCVELIST:CVE-2021-24731
HistoryNov 08, 2021 - 5:35 p.m.

CVE-2021-24731 Pie Register < 3.7.1.6 - Unauthenticated SQL Injection

2021-11-0817:35:16
CWE-89
WPScan
www.cve.org
2
cve-2021-24731
pie register
sql injection
wordpress plugin
rest api

EPSS

0.178

Percentile

96.2%

The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an SQL injection.

CNA Affected

[
  {
    "product": "Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes",
    "vendor": "Unknown",
    "versions": [
      {
        "lessThan": "3.7.1.6",
        "status": "affected",
        "version": "3.7.1.6",
        "versionType": "custom"
      }
    ]
  }
]

EPSS

0.178

Percentile

96.2%