CVE-2021-24392
Description
An id GET parameter of the WordPress Membership SwiftCloud.io WordPress plugin through 1.0 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
CWE
- CWE-89 — CWE-89 SQL Injection
Affected
- Unknown / WordPress Membership SwiftCloud.io — v=1.0 ≤1.0 [affected]
CVSS
- (none)
References
- https://wpscan.com/vulnerability/68530e63-bba3-4a9a-ae83-516684aa5dc6 x_refsource_MISC
- https://codevigilant.com/disclosure/2021/wp-plugin-club-management-software/ x_refsource_MISC
Source
cvelistV5-main/cves/2021/24xxx/CVE-2021-24392.json