CVE-2021-24755SQL Injection in Mycred

CWE-89SQL Injection4 documents4 sources
Severity
8.8HIGHNVD
EPSS
0.7%
top 28.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 29
Latest updateNov 30

Description

The myCred WordPress plugin before 2.3 does not validate or escape the fields parameter before using it in a SQL statement, leading to an SQL injection exploitable by any authenticated user

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

NVDwpexperts/mycred< 2.3

🔴Vulnerability Details

3
GHSA
GHSA-9q3v-827r-c9mw: The myCred WordPress plugin before 22021-11-30
CVEList
myCred < 2.3 - Subscriber+ SQL Injection2021-11-29
VulnCheck
wpexperts mycred Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2021
CVE-2021-24755 — SQL Injection in Wpexperts Mycred | cvebase