Unvalidated input in the AccessPress Social Icons plugin, versions before 1.8.1, did not sanitise its widget attribute, allowing accounts with post permission, such as author, to perform SQL injections.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2021-03-18T14:57:50
Updated: 2024-08-03T19:21:18.374Z
Reserved: 2021-01-14T00:00:00
Link: CVE-2021-24143
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-03-18T15:15:15.213
Modified: 2024-11-21T05:52:27.500
Link: CVE-2021-24143
Redhat
No data.