CVE-2021-24630
The Schreikasten WordPress plugin through 0.14.18 does not sanitise or escape the id GET parameter before using it in SQL statements in the comments dashboard from various actions, leading to authenticated SQL Injections which can be exploited by users…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.57%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Schreikasten WordPress plugin through 0.14.18 does not sanitise or escape the id GET parameter before using it in SQL statements in the comments dashboard from various actions, leading to authenticated SQL Injections which can be exploited by users as low as author
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.57% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- schreikasten project/schreikasten
- Source
- contact@wpscan.com
References
- https://codevigilant.com/disclosure/2021/wp-plugin-schreikasten/Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/a0787dae-a4b7-4248-9960-aaffabfaeb9fExploit, Third Party Advisory
- https://codevigilant.com/disclosure/2021/wp-plugin-schreikasten/Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/a0787dae-a4b7-4248-9960-aaffabfaeb9fExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.