SQL Injection Vulnerability in WordPress Plugin by Vulnerable Vendor
CVE-2021-21931
7.7HIGH
What is CVE-2021-21931?
An SQL injection vulnerability exists within a WordPress plugin, caused by improperly handled input in the 'stat_filter' parameter. This flaw allows an attacker to execute unauthorized SQL commands through crafted HTTP requests. The attack can be initiated by any authenticated user or through cross-site request forgery techniques, potentially compromising the integrity and security of the underlying database.
Affected Version(s)
Advantech Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021)