CVE-2021-24390
06.09.2021, 11:15
A proid GET parameter of the WordPressAlipay|Tenpay|PayPal WordPress plugin through 3.7.2 is not sanitised, properly escaped or validated before inserting to a SQL statement not delimited by quotes, leading to SQL injection.
Vendor | Product | Version |
---|---|---|
alipay_project | alipay | 𝑥 ≤ 3.7.2 |
𝑥
= Vulnerable software versions