Unvalidated input in the AccessPress Social Icons plugin, versions before 1.8.1, did not sanitise its widget attribute, allowing accounts with post permission, such as author, to perform SQL injections.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-11057 | Unvalidated input in the AccessPress Social Icons plugin, versions before 1.8.1, did not sanitise its widget attribute, allowing accounts with post permission, such as author, to perform SQL injections. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-03T19:21:18.374Z
Reserved: 2021-01-14T00:00:00
Link: CVE-2021-24143
No data.
Status : Modified
Published: 2021-03-18T15:15:15.213
Modified: 2024-11-21T05:52:27.500
Link: CVE-2021-24143
No data.
OpenCVE Enrichment
No data.
EUVD