CVE Database
/

CVE-2021-24877

Back to search

CVE-2021-24877

Published: Nov 23, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

The MainWP Child WordPress plugin before 4.1.8 does not validate the orderby and order parameter before using them in a SQL statement, leading to an SQL injection exploitable by high privilege users such as admin when the Backup and Staging by WP Time Capsule plugin is installed

VendorProductVersions

Unknown

MainWP Child - Securely connects sites to the MainWP WordPress Manager Dashboard

affected
4.1.8 - < 4.1.8

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now