PT-2021-15936 · WordPress · Wordpress Page Contact
Syed Sheeraz Ali
·
Published
2021-09-20
·
Updated
2021-09-29
·
CVE-2021-24403
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WordPress Page Contact plugin versions prior to 1.1
Description
The Orders functionality in the WordPress Page Contact plugin has an issue where the
order id parameter is not properly sanitized, escaped, or validated before being inserted into a SQL statement. This leads to SQL injection and the feature is accessible to low-privilege users, such as contributors.Recommendations
For WordPress Page Contact plugin versions prior to 1.1, update to version 1.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Orders functionality to high-privilege users until the update is applied. Avoid using the
order id parameter in the affected functionality until the issue is resolved.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wordpress Page Contact