Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-24786

The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue
Exploit prediction scoring system (EPSS) score
EPSS Score 0.046
EPSS Ranking 88.7%
CVSS Severity
CVSS v3 Score 7.2
CVSS v2 Score 6.5
Products affected by CVE-2021-24786


Contact Us

Shodan ® - All rights reserved