CVE-2021-24726
WP Simple Booking Calendar <= 2.0.6 (before 07/12/2021) - Authenticated SQL Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The WP Simple Booking Calendar WordPress plugin before 2.0.6 did not escape, validate or sanitise the orderby parameter in its Search Calendars action, before using it in a SQL statement, leading to an authenticated SQL injection issue
El plugin WP Simple Booking Calendar de WordPress versiones anteriores a 2.0.6, no escapaba, comprobaba o saneaba el parámetro orderby en su acción Search Calendars, antes de usarlo en una sentencia SQL, conllevando a un problema de inyección SQL autenticada
The WP Simple Booking Calendar WordPress plugin before 2.0.7 did not escape, validate or sanitise the orderby parameter in its Search Calendars action, before using it in a SQL statement, leading to an authenticated SQL injection issue
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-14 CVE Reserved
- 2021-08-06 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-08-05 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/f85b6033-d7c1-45b7-b3b0-8967f7373bb8 | 2024-08-03 | |
https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=29176 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wpsimplebookingcalendar Search vendor "Wpsimplebookingcalendar" | Wp Simple Booking Calendar Search vendor "Wpsimplebookingcalendar" for product "Wp Simple Booking Calendar" | < 2.0.6 Search vendor "Wpsimplebookingcalendar" for product "Wp Simple Booking Calendar" and version " < 2.0.6" | wordpress |
Affected
|