Vulnerability Details CVE-2021-38324
The SP Rental Manager WordPress plugin is vulnerable to SQL Injection via the orderby parameter found in the ~/user/shortcodes.php file which allows attackers to retrieve information contained in a site's database, in versions up to and including 1.5.3.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 65.7%
CVSS Severity
CVSS v3 Score 8.2
CVSS v2 Score 5.0
Products affected by CVE-2021-38324
-
cpe:2.3:a:smartypantsplugins:sp_rental_manager:1.5.3