CVE Database
/

CVE-2021-24361

Back to search

CVE-2021-24361

Published: Jun 21, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sanitise or validate some of its POST parameters, which are then used in a SQL statement, leading to unauthenticated SQL Injection issues.

VendorProductVersions

AyeCode Ltd

Location Manager

affected
2.1.0.10 - < 2.1.0.10

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now