CVE-2021-24629
08.11.2021, 18:15
The Post Content XMLRPC WordPress plugin through 1.0 does not sanitise or escape multiple GET/POST parameters before using them in SQL statements in the admin dashboard, leading to an authenticated SQL Injections
Vendor | Product | Version |
---|---|---|
post_content_xmlrpc_project | post_content_xmlrpc | 𝑥 ≤ 1.0 |
𝑥
= Vulnerable software versions