cleantalk
Vulnerabilities and Security Researches

MainWP Child – Securely Connects Sites to the MainWP WordPress Manager Dashboard, CVE-2021-24877

CVE, Research URL

CVE-2021-24877

Published on
Nov 24, 2021
Research Description
The MainWP Child WordPress plugin before 4.1.8 does not validate the orderby and order parameter before using them in a SQL statement, leading to an SQL injection exploitable by high privilege users such as admin when the Backup and Staging by WP Time Capsule plugin is installed
Affected versions
max 3.4.5.
Status
vulnerable