PT-2021-15929 · WordPress · Gseor – Wordpress Seo Plugin
Syed Sheeraz Ali
·
Published
2021-09-20
·
Updated
2021-09-28
·
CVE-2021-24396
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GSEOR – WordPress SEO Plugin versions through 1.3
Description
The issue arises from the
pageid GET parameter not being sanitised, escaped, or validated before being inserted into a SQL statement, leading to SQL injection. This allows for potential manipulation of database queries.Recommendations
For GSEOR – WordPress SEO Plugin versions through 1.3, consider disabling the
pageid GET parameter until a patch is available to prevent SQL injection attacks. Restrict access to SQL queries to minimize the risk of exploitation. Avoid using the pageid parameter in affected API endpoints until the issue is resolved.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gseor – Wordpress Seo Plugin