CVE-2021-24451

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
06/07/2021
Last modified:
09/07/2021

Description

The Export Users With Meta WordPress plugin before 0.6.5 did not escape the list of roles to export before using them in a SQL statement in the export functionality, available to admins, leading to an authenticated SQL Injection.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:export_users_with_meta_project:export_users_with_meta:*:*:*:*:*:wordpress:*:* 0.6.5 (excluding)