CVE-2021-24360

CVE-2021-24360: Yes/No Chart < 1.0.12 - Authenticated (contributor+) Blind SQL Injection

Vendor Unknown
Product Yes/No Chart
Weakness CWE-89 · SQLi
Published June 14, 2021
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

The Yes/No Chart WordPress plugin before 1.0.12 did not sanitise its sid shortcode parameter before using it in a SQL statement, allowing medium privilege users (contributor+) to perform Blind SQL Injection attacks

Key dates

02Disclosure timeline

June 14, 2021 CVE published
August 3, 2024 Record updated