VYPR

REST API TO MiniProgram

by REST API TO MiniProgram

CVEs (1)

  • CVE-2024-8484HigSep 25, 2024
    risk 0.49cvss 7.5epss 0.04

    The REST API TO MiniProgram plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/watch-life-net/v1/comment/getcomments REST API endpoint in all versions up to, and including, 4.7.1 due to insufficient escaping on the user supplied…