cleantalk
Vulnerabilities and Security Researches

MainWP Child Reports, CVE-2021-24754

CVE, Research URL

CVE-2021-24754

Application

MainWP Child Reports

Published on
Oct 18, 2021
Research Description
The MainWP Child Reports WordPress plugin before 2.0.8 does not validate or sanitise the order parameter before using it in a SQL statement in the admin dashboard, leading to an SQL injection issue
Affected versions
Min -, max 2.0.8.
Status
vulnerable