
CVE-2021-24458 – Popup box < 2.3.4 - Authenticated Blind SQL Injections
https://notcve.org/view.php?id=CVE-2021-24458
29 Jun 2021 — The get_ays_popupboxes() and get_popup_categories() functions of the Popup box WordPress plugin before 2.3.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard Las funciones get_ays_popupboxes() y get_popup_categories() del plugin Popup box de WordPress versiones anteriores a 2.3.4, no usaban la lista blanca ni comprobaban el parámetro orderby antes de usarlo en las sentencias ... • https://wpscan.com/vulnerability/8a588266-54cd-4779-adcf-f9b9e226c297 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2021-24459 – Survey Maker < 1.5.6 - Authenticated Blind SQL Injections
https://notcve.org/view.php?id=CVE-2021-24459
29 Jun 2021 — The get_results() and get_items() functions in the Survey Maker WordPress plugin before 1.5.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard Las funciones get_results() y get_items() del plugin de WordPress Survey Maker versiones anteriores a 1.5.6, no usaban la lista blanca ni comprobaban el parámetro orderby antes de usarlo en las sentencias SQL que se pasaban a las llama... • https://wpscan.com/vulnerability/3fafbec0-55e4-41cf-8402-1b57b6615225 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2021-24460 – Popup Like box - Page Plugin < 3.5.3 - Authenticated Blind SQL Injections
https://notcve.org/view.php?id=CVE-2021-24460
29 Jun 2021 — The get_fb_likeboxes() function in the Popup Like box – Page Plugin WordPress plugin before 3.5.3 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard La función get_fb_likeboxes() del plugin de WordPress Popup Like box versiones anteriores a 3.5.3, no usaba la lista blanca ni comprobaba el parámetro orderby antes de usarlo en las sentencias SQL pasadas a las llamadas a la base d... • https://wpscan.com/vulnerability/9c0164f2-464b-4876-a48f-c0ebd63cf397 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2021-24461 – FAQ Builder < 1.3.6 - Authenticated Blind SQL Injections
https://notcve.org/view.php?id=CVE-2021-24461
29 Jun 2021 — The get_faqs() function in the FAQ Builder AYS WordPress plugin before 1.3.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard La función get_faqs() del plugin de WordPress FAQ Builder AYS versiones anteriores a 1.3.6, no usaba la lista blanca ni comprobaba el parámetro orderby antes de usarlo en las sentencias SQL pasadas a las llamadas a la base de datos get_results(), conll... • https://wpscan.com/vulnerability/311974b5-6d6e-4b47-a33d-6d8f468aa528 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2021-24462 – Photo Gallery by Ays - Responsive Image Gallery < 4.4.4 - Authenticated Blind SQL Injections
https://notcve.org/view.php?id=CVE-2021-24462
29 Jun 2021 — The get_gallery_categories() and get_galleries() functions in the Photo Gallery by Ays – Responsive Image Gallery WordPress plugin before 4.4.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard Las funciones get_gallery_categories() y get_galleries() del plugin de WordPress Photo Gallery by Ays - Responsive Image Gallery versiones anteriores a 4.4.4, no usaban la lista blanca ... • https://wpscan.com/vulnerability/e24dac6d-de48-42c1-bdde-4a45fb331376 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2021-24463 – Image Slider by Ays - Responsive Slider and Carousel < 2.5.0 - Authenticated Blind SQL Injection
https://notcve.org/view.php?id=CVE-2021-24463
29 Jun 2021 — The get_sliders() function in the Image Slider by Ays- Responsive Slider and Carousel WordPress plugin before 2.5.0 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard La función get_sliders() del plugin de WordPress Image Slider by Ays- Responsive Slider and Carousel versiones anteriores a 2.5.0, no usaba la lista blanca ni comprobaba el parámetro orderby antes de usarlo en las... • https://wpscan.com/vulnerability/994e6198-f0e9-4e30-989f-b5a3dfe95ded • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2021-24483 – Poll Maker < 3.2.1 - Authenticated Blind SQL Injections
https://notcve.org/view.php?id=CVE-2021-24483
29 Jun 2021 — The get_poll_categories(), get_polls() and get_reports() functions in the Poll Maker WordPress plugin before 3.2.1 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard Las funciones get_poll_categories(), get_polls() y get_reports() del plugin de WordPress Poll Maker versiones anteriores a 3.2.1, no usaban la lista blanca o comprobaban el parámetro orderby antes de usarlo en las ... • https://wpscan.com/vulnerability/0dc931c6-1fce-4d70-a658-a4bbab10dab3 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2021-24484 – Secure Copy Content Protection and Content Locking < 2.6.7 - Authenticated Blind SQL Injections
https://notcve.org/view.php?id=CVE-2021-24484
29 Jun 2021 — The get_reports() function in the Secure Copy Content Protection and Content Locking WordPress plugin before 2.6.7 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard La función get_reports() del plugin de WordPress Secure Copy Content Protection and Content Locking versiones anteriores a 2.6.7, no usaba la lista blanca o comprobaba el parámetro orderby antes de usarlo en las se... • https://wpscan.com/vulnerability/9ce0153d-4a8b-4215-b6b6-15ca68c4f52c • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2016-10921 – Photo Gallery by Ays – Responsive Image Gallery < 1.0.1 - SQL Injection
https://notcve.org/view.php?id=CVE-2016-10921
11 Jul 2016 — The gallery-photo-gallery plugin before 1.0.1 for WordPress has SQL injection. El plugin gallery-photo-gallery versiones anteriores a 1.0.1 para WordPress, presenta una inyección SQL. The Photo Gallery by Ays – Responsive Image Gallery plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to 1.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to append additi... • https://wordpress.org/plugins/gallery-photo-gallery/#developers • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •