SQL Injection Vulnerability in Email Log WordPress Plugin

SQL Injection Vulnerability in Email Log WordPress Plugin

CVE-2021-24758 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

The Email Log WordPress plugin before 2.4.7 does not properly validate, sanitise and escape the "orderby" and "order" GET parameters before using them in SQL statement in the admin dashboard, leading to SQL injections

Learn more about our Wordpress Pen Testing.