CVE-2021-24580 – Side Menu Lite < 2.2.6 - Authenticated SQL Injection
https://notcve.org/view.php?id=CVE-2021-24580
The Side Menu Lite WordPress plugin before 2.2.6 does not sanitise user input from the List page in the admin dashboard before using it in SQL statement, leading to a SQL Injection issue El plugin Side Menu Lite de WordPress versiones anteriores a 2.2.6, no sanea la entrada del usuario desde la página de la Lista en el panel de administración antes de usarla en una sentencia SQL, conllevando a un problema de inyección SQL. The Side Menu Lite WordPress plugin before 2.2.6 does not sanitise user input from the List page in the admin dashboard before using it in SQL statement, leading to a SQL Injection issue. • https://wpscan.com/vulnerability/2faccd1b-4b1c-4b3e-b917-de2d05e860f8 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2021-24521 – Side Menu Lite < 2.2.1 - Authenticated SQL Injection
https://notcve.org/view.php?id=CVE-2021-24521
The Side Menu Lite – add sticky fixed buttons WordPress plugin before 2.2.1 does not properly sanitize input values from the browser when building an SQL statement. Users with the administrator role or permission to manage this plugin could perform an SQL Injection attack. El plugin de WordPress Side Menu Lite - add sticky fixed buttons versiones anteriores a 2.2.1, no sanea apropiadamente los valores de entrada del navegador cuando se construye una sentencia SQL. Unos usuarios con el rol de administrador o con permiso para administrar este plugin podrían llevar a cabo un ataque de inyección SQL • https://github.com/pang0lin/CVEproject/blob/main/wordpress_side-menu-lite_sqli.md https://wpscan.com/vulnerability/eb21ebc5-265c-4378-b2c6-62f6bc2f69cd • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2021-24348 – Side Menu < 3.1.5 - Authenticated (admin+) SQL Injection
https://notcve.org/view.php?id=CVE-2021-24348
The menu delete functionality of the Side Menu – add fixed side buttons WordPress plugin before 3.1.5, available to Administrator users takes the did GET parameter and uses it into an SQL statement without proper sanitisation, validation or escaping, therefore leading to a SQL Injection issue La funcionalidad menu delete del plugin Side Menu - add fixed side buttons de WordPress versiones anteriores a 3.1.5, disponible para los usuarios Administradores, toma el parámetro GET y lo usa en una sentencia SQL sin el saneamiento, comprobación o escape apropiado, conllevando por lo tanto a un problema de Inyección SQL • https://codevigilant.com/disclosure/2021/wp-plugin-side-menu https://wpscan.com/vulnerability/e0ca257e-6e78-4611-a9ad-be43d37cf474 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •