VYPR
Unrated severityNVD Advisory· Published Aug 2, 2021· Updated Aug 3, 2024

Popup box < 2.3.4 - Authenticated Blind SQL Injections

CVE-2021-24458

Description

The get_ays_popupboxes() and get_popup_categories() functions of the Popup box WordPress plugin before 2.3.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Ays Pro/Popup Boxllm-fuzzy2 versions
    <2.3.4+ 1 more
    • (no CPE)range: <2.3.4
    • (no CPE)range: 2.3.4

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.