CVE Database
/

CVE-2021-39351

Back to search

CVE-2021-39351

Published: Oct 6, 2021

Modified: Feb 14, 2025

PUBLISHED

Description

The WP Bannerize WordPress plugin is vulnerable to authenticated SQL injection via the id parameter found in the ~/Classes/wpBannerizeAdmin.php file which allows attackers to exfiltrate sensitive information from vulnerable sites. This issue affects versions 2.0.0 - 4.0.2.

VendorProductVersions

WP Bannerize

WP Bannerize

affected
2.0.0 - 4.0.2 4.0.2

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now