Unrated severityNVD Advisory· Published Mar 7, 2022· Updated Aug 3, 2024
Tradetracker-Store < 4.6.60 - Admin+ SQL Injection
CVE-2021-24778
Description
The test parameter of the xmlfeed in the Tradetracker-Store WordPress plugin before 4.6.60 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
Affected products
1- Range: 4.6.60
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/e37f9aa6-e409-4155-b8e4-566c5bce58d6mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.