Mediamatic < 2.8.1 - Subscriber+ SQL Injection
CVE-2021-24848
8.8HIGH
What is CVE-2021-24848?
The mediamaticAjaxRenameCategory AJAX action of the Mediamatic WordPress plugin before 2.8.1, available to any authenticated user, does not sanitise the categoryID parameter before using it in a SQL statement, leading to an SQL injection
Affected Version(s)
Mediamatic – Media Library Folders 2.8.1