PT-2021-15936 · WordPress · Wordpress Page Contact

Syed Sheeraz Ali

·

Published

2021-09-20

·

Updated

2021-09-29

·

CVE-2021-24403

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WordPress Page Contact plugin versions prior to 1.1
Description The Orders functionality in the WordPress Page Contact plugin has an issue where the order id parameter is not properly sanitized, escaped, or validated before being inserted into a SQL statement. This leads to SQL injection and the feature is accessible to low-privilege users, such as contributors.
Recommendations For WordPress Page Contact plugin versions prior to 1.1, update to version 1.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Orders functionality to high-privilege users until the update is applied. Avoid using the order id parameter in the affected functionality until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24403

Affected Products

Wordpress Page Contact