CVE-2021-44779
Description
Unauthenticated SQL Injection (SQLi) vulnerability discovered in [GWA] AutoResponder WordPress plugin (versions <= 2.3), vulnerable at (&listid). No patched version available, plugin closed.
CWE
- CWE-89 — CWE-89 SQL Injection
Affected
- G.J.P. / [GWA] AutoResponder (WordPress plugin) — v=<= 2.3 ≤2.3 [affected]
CVSS
- 3.1 score=7.3 severity=HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
References
- https://wordpress.org/plugins/gwa-autoresponder/ x_refsource_CONFIRM
- https://patchstack.com/database/vulnerability/gwa-autoresponder/wordpress-gwa-autoresponder-plugin-2-3-unauthenticated-sql-injection-sqli-vulnerability x_refsource_CONFIRM
Source
cvelistV5-main/cves/2021/44xxx/CVE-2021-44779.json