CVE-2021-24396
Description
A pageid GET parameter of the GSEOR – WordPress SEO Plugin WordPress plugin through 1.3 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
CWE
- CWE-89 — CWE-89 SQL Injection
Affected
- Unknown / GSEOR – WordPress SEO Plugin — v=1.3 ≤1.3 [affected]
CVSS
- (none)
References
- https://wpscan.com/vulnerability/28687291-2369-49e0-8905-dc4359454830 x_refsource_MISC
- https://codevigilant.com/disclosure/2021/wp-plugin-gseor/ x_refsource_MISC
Source
cvelistV5-main/cves/2021/24xxx/CVE-2021-24396.json