Back to search
CVE-2021-24731
Published: Nov 8, 2021
Modified: Aug 3, 2024
PUBLISHED
Description
The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an SQL injection.
| Vendor | Product | Versions |
|---|---|---|
Unknown | Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes | affected 3.7.1.6 - < 3.7.1.6 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now