VYPR
High severity8.8NVD Advisory· Published Jan 10, 2022· Updated Jun 17, 2026

CVE-2021-25054

CVE-2021-25054

Description

The WPcalc WordPress plugin through 2.1 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authenticated SQL Injection vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:wow-company:wpcalc:*:*:*:*:*:wordpress:*:*
    Range: <=2.1
  • WordPress/WPcalccpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <=2.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.