Логотип exploitDog
bind:CVE-2021-24340
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-24340

Количество 2

Количество 2

nvd логотип

CVE-2021-24340

больше 4 лет назад

The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query. Additionally, the page, which should have been accessible to administrator only, was also available to any visitor, including unauthenticated ones.

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-9mj4-xv45-qwq2

больше 3 лет назад

The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query. Additionally, the page, which should have been accessible to administrator only, was also available to any visitor, including unauthenticated ones.

EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-24340

The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query. Additionally, the page, which should have been accessible to administrator only, was also available to any visitor, including unauthenticated ones.

CVSS3: 7.5
83%
Высокий
больше 4 лет назад
github логотип
GHSA-9mj4-xv45-qwq2

The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query. Additionally, the page, which should have been accessible to administrator only, was also available to any visitor, including unauthenticated ones.

83%
Высокий
больше 3 лет назад

Уязвимостей на страницу