VulnerabilityModified
CVE-2021-24138
Unvalidated input in the AdRotate WordPress plugin, versions before 5.8.4, leads to Authenticated SQL injection via param "id".
MEDIUM 5.5EPSS 1.23%
Does this matter?
Lower severity and a low EPSS score (1.23%). Track it; it rarely justifies an emergency change on its own.
Description
Unvalidated input in the AdRotate WordPress plugin, versions before 5.8.4, leads to Authenticated SQL injection via param "id". This requires an admin privileged user.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:L
- EPSS
- 1.23% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- ajdg/adrotate
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/aafac655-3616-4b27-9d0f-1cbc2faf0151Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/aafac655-3616-4b27-9d0f-1cbc2faf0151Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.