CVE-2021-24791
The Header Footer Code Manager WordPress plugin before 1.1.14 does not validate and escape the "orderby" and "order" request parameters before using them in a SQL statement when viewing the Snippets admin dashboard, leading to SQL injections
- Affected products
- Header Footer Code Manager
- Draftpress Header Footer Code Manager
- < 1.1.14
- Fix
- Available
- CVSS 3.1
- 7.2 HIGH
- EPSS
- 5.1% (92th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2021-11-08
CVE-2021-24791 at NVD
1 known exploit for CVE-2021-24791
Proof-of-concept code and exploit modules indexed by Sploitus