CVE-2021-24772

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
17/11/2021
Last modified:
19/11/2021

Description

The Stream WordPress plugin before 3.8.2 does not sanitise and validate the order GET parameter from the Stream Records admin dashboard before using it in a SQL statement, leading to an SQL injection issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:xwp:stream:*:*:*:*:*:wordpress:*:* 3.8.2 (excluding)