Security Advisory

CVE-2021-24451

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-07-06 11:03:34
Last updated 2024-08-03 19:28:23
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The Export Users With Meta WordPress plugin before 0.6.5 did not escape the list of roles to export before using them in a SQL statement in the export functionality, available to admins, leading to an authenticated SQL Injection.