High severity8.8NVD Advisory· Published Nov 17, 2021· Updated Jun 17, 2026
CVE-2021-24772
CVE-2021-24772
Description
The Stream WordPress plugin before 3.8.2 does not sanitise and validate the order GET parameter from the Stream Records admin dashboard before using it in a SQL statement, leading to an SQL injection issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- plugins.trac.wordpress.org/changeset/2615811/streamnvdPatchThird Party Advisory
- wpscan.com/vulnerability/b9d4f2ad-2f12-4822-817d-982a016af85dnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.