WordPress plugin是WordPress开源的一个应用插件。 WordPress plugin 的Download Monitor插件 4.4.5之前版本存在SQL注入漏洞,该漏洞源于在SQL语句中使用“orderby”GET参数之前,未正确验证和转义该参数,从而导致SQL注入问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Download Monitor | 4.4.5 ~ 4.4.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | The Download Monitor plugin for WordPress is vulnerable to SQL injection via the 'orderby' parameter in versions before 4.4.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with administrator-level permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-24786.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-25000 | Booster for WooCommerce < 5.4.9 - Reflected Cross-Site Scripting in General Module | |
| CVE-2021-25040 | Booking Calendar < 8.9.2 - Reflected Cross-Site Scripting | |
| CVE-2021-25030 | Events Made Easy < 2.2.36 - Subscriber+ SQL Injection | |
| CVE-2021-25027 | PowerPack Addons for Elementor < 2.6.2 - Reflected Cross-Site Scripting | |
| CVE-2021-25023 | Speed Booster Pack < 4.3.3.1 - Admin+ SQL Injection | |
| CVE-2021-25022 | UpdraftPlus < 1.16.66 - Reflected Cross-Site Scripting | |
| CVE-2021-25021 | OMGF < 4.5.12 - Admin+ Arbitrary Folder Deletion via Path Traversal | |
| CVE-2021-25020 | CAOS < 4.1.9 - Admin+ Arbitrary Folder Deletion via Path Traversal | |
| CVE-2021-25016 | Chaty < 2.8.3 - Reflected Cross-Site Scripting | |
| CVE-2021-25001 | Booster for WooCommerce < 5.4.9 - Reflected Cross-Site Scripting in Product XML Feeds Modu | |
| CVE-2021-24680 | WP Travel Engine < 5.3.1 - Editor+ Stored Cross-Site Scripting | |
| CVE-2021-24999 | Booster for Woocommerce < 5.4.9 - Reflected Cross-Site Scripting in PDF Invoicing Module | |
| CVE-2021-24991 | WooCommerce PDF Invoices & Packing Slips < 2.10.5 - Reflected Cross-Site Scripting | |
| CVE-2021-24973 | Site Reviews < 5.17.3 - Unauthenticated Stored Cross-Site Scripting | |
| CVE-2021-24964 | LiteSpeed Cache < 4.4.4 - IP Check Bypass to Unauthenticated Stored XSS | |
| CVE-2021-24963 | LiteSpeed Cache < 4.4.4 - Admin+ Reflected Cross-Site Scripting | |
| CVE-2021-24893 | Stars Rating < 3.5.1 - Comments Denial of Service | |
| CVE-2021-24831 | Tab - Accordion, FAQ < 1.3.2 - Unauthenticated AJAX Calls | |
| CVE-2021-24828 | Mortgage Calculator / Loan Calculator < 1.5.17 - Contributor+ Stored Cross-Site Scripting |
No comments yet