← back
CVE-2021-24200

wpDataTables < 3.4.2 - Blind SQL Injection via length Parameter

EPSS 1.3%CWE-89
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 1.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
12 Apr 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user to perform Boolean-based blind SQL Injection in the table list page on the endpoint /wp-admin/admin-ajax.php?action=get_wdtable&table_id=1, on the 'length' HTTP POST parameter. This allows an attacker to access all the data in the database and obtain access to the WordPress application.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →