VulnerabilityModified
CVE-2021-24748
The Email Before Download WordPress plugin before 6.8 does not properly validate and escape the order and orderby GET parameters before using them in SQL statements, leading to authenticated SQL injection issues
HIGH 8.8EPSS 1.32%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.32%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Email Before Download WordPress plugin before 6.8 does not properly validate and escape the order and orderby GET parameters before using them in SQL statements, leading to authenticated SQL injection issues
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.32% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- mandsconsulting/email before download
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/a8625b84-337d-4c4d-a698-73e59d1f8ee1Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/a8625b84-337d-4c4d-a698-73e59d1f8ee1Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.