Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-24877

The MainWP Child WordPress plugin before 4.1.8 does not validate the orderby and order parameter before using them in a SQL statement, leading to an SQL injection exploitable by high privilege users such as admin when the Backup and Staging by WP Time Capsule plugin is installed
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 67.6%
CVSS Severity
CVSS v3 Score 7.2
CVSS v2 Score 6.0
Products affected by CVE-2021-24877


Contact Us

Shodan ® - All rights reserved