CVE-2021-24348
The menu delete functionality of the Side Menu – add fixed side buttons WordPress plugin before 3.1.5, available to Administrator users takes the did GET parameter and uses it into an SQL statement without proper sanitisation, validation or escaping,…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.57%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The menu delete functionality of the Side Menu – add fixed side buttons WordPress plugin before 3.1.5, available to Administrator users takes the did GET parameter and uses it into an SQL statement without proper sanitisation, validation or escaping, therefore leading to a SQL Injection issue
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.57% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- wow-estore/side menu
- Source
- contact@wpscan.com
References
- https://codevigilant.com/disclosure/2021/wp-plugin-side-menu/Exploit, Patch, Third Party Advisory
- https://wpscan.com/vulnerability/e0ca257e-6e78-4611-a9ad-be43d37cf474Exploit, Third Party Advisory
- https://codevigilant.com/disclosure/2021/wp-plugin-side-menu/Exploit, Patch, Third Party Advisory
- https://wpscan.com/vulnerability/e0ca257e-6e78-4611-a9ad-be43d37cf474Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.