Unrated severityNVD Advisory· Published Aug 2, 2021· Updated Aug 3, 2024
FAQ Builder < 1.3.6 - Authenticated Blind SQL Injections
CVE-2021-24461
Description
The get_faqs() function in the FAQ Builder AYS WordPress plugin before 1.3.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard
Affected products
1- Range: 1.3.6
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/311974b5-6d6e-4b47-a33d-6d8f468aa528mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.