mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-26 09:28:10 +02:00
820 B
820 B
CVE-2021-24754
Description
The MainWP Child Reports WordPress plugin before 2.0.8 does not validate or sanitise the order parameter before using it in a SQL statement in the admin dashboard, leading to an SQL injection issue
POC
Reference
- https://wpscan.com/vulnerability/132118aa-4b72-4eaa-8aa1-6ad7b0c7f495
- https://wpscan.com/vulnerability/132118aa-4b72-4eaa-8aa1-6ad7b0c7f495
Github
No PoCs found on GitHub currently.