Security Advisory

CVE-2021-24606

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-09-20 10:06:32
Last updated 2024-08-03 19:35:20
Assigner WPScan
State PUBLISHED

Description

The Availability Calendar WordPress plugin before 1.2.1 does not escape the category attribute from its shortcode before using it in a SQL statement, leading to a SQL Injection issue, which can be exploited by any user able to add shortcode to posts/pages, such as contributor+