Lucene search

K
wpvulndbWpvulndbWPVDB-ID:B2466272-FAE1-414E-8976-B8A1A92380BB
HistorySep 08, 2021 - 12:00 a.m.

SP Rental Manager <= 1.5.3 - Unauthenticated SQL Injection

2021-09-0800:00:00
wpscan.com
14

0.002 Low

EPSS

Percentile

61.1%

The plugin is vulnerable to SQL Injection via the orderby parameter found in the ~/user/shortcodes.php file which allows attackers to retrieve information contained in a site’s database.

CPENameOperatorVersion
sp-rental-managereq*

0.002 Low

EPSS

Percentile

61.1%

Related for WPVDB-ID:B2466272-FAE1-414E-8976-B8A1A92380BB