PT-2024-10893 · WordPress · Wp Fastest Cache

Marc Montpas

·

Published

2024-01-16

·

Updated

2024-01-19

·

CVE-2021-24869

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP Fastest Cache versions prior to 0.9.5
Description The issue is related to the set urls with terms method, which does not properly escape user input before using it in a SQL statement. This leads to an SQL injection that can be exploited by low-privilege users, such as subscribers.
Recommendations For versions prior to 0.9.5, update to version 0.9.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the set urls with terms method until a patch is available.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2021-24869

Affected Products

Wp Fastest Cache