Unrated severityNVD Advisory· Published Feb 28, 2022· Updated Aug 3, 2024
WP Cloudy < 4.4.9 - Admin+ SQL Injection
CVE-2021-24864
Description
The WP Cloudy, weather plugin WordPress plugin before 4.4.9 does not escape the post_id parameter before using it in a SQL statement in the admin dashboard, leading to a SQL Injection issue
Affected products
1- Range: 4.4.9
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- plugins.trac.wordpress.org/changeset/2615400mitrex_refsource_CONFIRM
- wpscan.com/vulnerability/e3b9ee9f-602d-4e9d-810c-e1e3ba604464mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.