PT-2024-10887 · WordPress · Wp Editor

Khanh

+1

·

Published

2024-01-16

·

Updated

2024-01-23

·

CVE-2021-24151

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP Editor WordPress plugin version 1.2.6 and earlier
Description The issue is related to an authenticated blind SQL injection problem. It occurs because the plugin does not properly sanitise or validate its setting fields, allowing an arbitrary parameter to be used when saving settings. This can be exploited by an admin or higher-privileged user.
Recommendations For WP Editor WordPress plugin version 1.2.6 and earlier, update to version 1.2.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the settings save functionality to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2021-24151

Affected Products

Wp Editor