Exploitation Summary
EIP tracks 1 public exploit for CVE-2021-24959. PoCs published by RandomRobbieBF.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2021-24959, an SQL injection vulnerability in the WP Email Users WordPress plugin. The script automates the process of checking the plugin version, logging in, and using sqlmap to dump database tables via the vulnerable 'data_raw' parameter.
Description
The WP Email Users WordPress plugin through 1.7.6 does not escape the data_raw parameter in the weu_selected_users_1 AJAX action, available to any authenticated users, allowing them to perform SQL injection attacks.
Exploits (1)
This repository contains a functional exploit for CVE-2021-24959, an SQL injection vulnerability in the WP Email Users WordPress plugin. The script automates the process of checking the plugin version, logging in, and using sqlmap to dump database tables via the vulnerable 'data_raw' parameter.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H