CVE Database
/

CVE-2021-24348

Back to search

CVE-2021-24348

Published: Jun 14, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

The menu delete functionality of the Side Menu – add fixed side buttons WordPress plugin before 3.1.5, available to Administrator users takes the did GET parameter and uses it into an SQL statement without proper sanitisation, validation or escaping, therefore leading to a SQL Injection issue

VendorProductVersions

Unknown

Side Menu – add fixed side buttons

affected
3.1.5 - < 3.1.5

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now