Comment Highlighter <= 0.13 - Authenticated SQL Injection
CVE-2021-24393
7.2HIGH
What is CVE-2021-24393?
A c GET parameter of the Comment Highlighter WordPress plugin through 0.13 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
Affected Version(s)
Comment Highlighter 0.13