Vulnerability Details CVE-2021-24554
The Paytm – Donation Plugin WordPress plugin through 1.3.2 does not sanitise, validate or escape the id GET parameter before using it in a SQL statement when deleting donations, leading to an authenticated SQL injection issue
Exploit prediction scoring system (EPSS) score
EPSS Score 0.162
EPSS Ranking 94.6%
CVSS Severity
CVSS v3 Score 7.2
CVSS v2 Score 6.5
Products affected by CVE-2021-24554
-
cpe:2.3:a:freelancetoindia:paytm-pay:*