CVE-2021-38324
09.09.2021, 19:15
The SP Rental Manager WordPress plugin is vulnerable to SQL Injection via the orderby parameter found in the ~/user/shortcodes.php file which allows attackers to retrieve information contained in a site's database, in versions up to and including 1.5.3.
Vendor | Product | Version |
---|---|---|
smartypantsplugins | sp_rental_manager | 𝑥 ≤ 1.5.3 |
𝑥
= Vulnerable software versions
References