CVE-2021-24520

CVE-2021-24520: Stock in & out <= 1.0.4 - Authenticated SQL Injection

Vendor Unknown
Product Stock in & out
Weakness CWE-89 · SQLi
Published August 9, 2021
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

The Stock in & out WordPress plugin through 1.0.4 lacks proper sanitization before passing variables to an SQL request, making it vulnerable to SQL Injection attacks. Users with a role of contributor or higher can exploit this vulnerability.

Key dates

02Disclosure timeline

August 9, 2021 CVE published
August 3, 2024 Record updated

Related vulnerabilities

04Related CVE