CVE-2021-24507
Astra Pro Addon < 3.5.2 - Unauthenticated SQL Injection
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 11.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
09 Aug 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from the astra_pagination_infinite and astra_shop_pagination_infinite AJAX action (available to both unauthenticated and authenticated user) before using them in SQL statement, leading to an SQL Injection issues
Affected products
Unknown · Astra Pro AddonWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →