Unrated severityNVD Advisory· Published Jun 14, 2021· Updated Aug 3, 2024
Sendit WP Newsletter <= 2.5.1 - Authenticated (admin+) SQL Injection
CVE-2021-24345
Description
The page lists-management feature of the Sendit WP Newsletter WordPress plugin through 2.5.1, available to Administrator users does not sanitise, validate or escape the id_lista POST parameter before using it in SQL statement, therefore leading to Blind SQL Injection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- WordPress/Sendit WP Newsletterdescription
- Range: <=2.5.1
Patches
Vulnerability mechanics
References
2- codevigilant.com/disclosure/2021/wp-plugin-sendit/mitrex_refsource_MISC
- wpscan.com/vulnerability/02ba4d8b-f4d2-42cd-9fae-b543e112fa04mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.