CVE-2021-24786
HIGH NUCLEIWordPress Download Monitor <4.4.5 - SQL Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-24786. PoCs published by Ron Jost. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit targets an SQL injection vulnerability in the WordPress Download Monitor plugin (CVE-2021-24786) by manipulating the 'orderby' GET parameter. It requires authentication and allows arbitrary SQL command execution via a crafted URL.
Description
The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue
Exploits (1)
This exploit targets an SQL injection vulnerability in the WordPress Download Monitor plugin (CVE-2021-24786) by manipulating the 'orderby' GET parameter. It requires authentication and allows arbitrary SQL command execution via a crafted URL.
Nuclei Templates (1)
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H