PT-2021-15929 · WordPress · Gseor – Wordpress Seo Plugin

Syed Sheeraz Ali

·

Published

2021-09-20

·

Updated

2021-09-28

·

CVE-2021-24396

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GSEOR – WordPress SEO Plugin versions through 1.3
Description The issue arises from the pageid GET parameter not being sanitised, escaped, or validated before being inserted into a SQL statement, leading to SQL injection. This allows for potential manipulation of database queries.
Recommendations For GSEOR – WordPress SEO Plugin versions through 1.3, consider disabling the pageid GET parameter until a patch is available to prevent SQL injection attacks. Restrict access to SQL queries to minimize the risk of exploitation. Avoid using the pageid parameter in affected API endpoints until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24396

Affected Products

Gseor – Wordpress Seo Plugin