CVE-2021-24669
EUVD-2021-1158108.11.2021, 18:15
The MAZ Loader – Preloader Builder for WordPress plugin before 1.3.3 does not validate or escape the loader_id parameter of the mzldr shortcode, which allows users with a role as low as Contributor to perform SQL injection.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| feataholic | maz_loader | 𝑥 < 1.3.3 |
𝑥
= Vulnerable software versions