PT-2021-15881 · WordPress · Sendit Wp Newsletter

Shreya Pohekar

·

Published

2021-06-14

·

Updated

2021-06-21

·

CVE-2021-24345

CVSS v3.1

6.6

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sendit WP Newsletter WordPress plugin versions 2.5.1 and earlier
Description The issue concerns the page lists-management feature of the plugin, which is accessible to Administrator users. It does not properly sanitise, validate, or escape the id lista POST parameter before using it in an SQL statement, leading to Blind SQL Injection.
Recommendations For Sendit WP Newsletter WordPress plugin versions 2.5.1 and earlier, update to a version that addresses the Blind SQL Injection issue in the page lists-management feature. As a temporary workaround, consider restricting access to the page lists-management feature to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24345

Affected Products

Sendit Wp Newsletter