CVE Database
/

CVE-2021-24337

Back to search

CVE-2021-24337

Published: Jun 7, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

The id GET parameter of one of the Video Embed WordPress plugin through 1.0's page (available via forced browsing) is not sanitised, validated or escaped before being used in a SQL statement, allowing low privilege users, such as subscribers, to perform SQL injection.

VendorProductVersions

Unknown

Video Embed

affected
1.0 - <= 1.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now