PoC Index

CVE-2021-24727

HIGH 8.8EPSS 1.7%

The StopBadBots WordPress plugin before 6.60 did not validate or escape the order and orderby GET parameter in some of its admin dashboard pages, leading to Authenticated SQL Injections

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
1.71% chance of exploitation in the next 30 days, 76th percentile
Published
2021-09-13
Updated
2024-08-03

Proof-of-concept exploits (2)

References

Related