In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sanitise or validate some of its POST parameters, which are then used in a SQL statement, leading to unauthenticated SQL Injection issues.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2021-06-21T19:18:14

Updated: 2024-08-03T19:28:23.436Z

Reserved: 2021-01-14T00:00:00

Link: CVE-2021-24361

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-06-21T20:15:08.347

Modified: 2021-06-24T19:44:22.053

Link: CVE-2021-24361

cve-icon Redhat

No data.