CVE-2021-24348

CVE-2021-24348: Side Menu < 3.1.5 - Authenticated (admin+) SQL Injection

Vendor Unknown
Product Side Menu – add fixed side buttons
Weakness CWE-89 · SQLi
Published June 14, 2021
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

The menu delete functionality of the Side Menu – add fixed side buttons WordPress plugin before 3.1.5, available to Administrator users takes the did GET parameter and uses it into an SQL statement without proper sanitisation, validation or escaping, therefore leading to a SQL Injection issue

Key dates

02Disclosure timeline

June 14, 2021 CVE published
August 3, 2024 Record updated