CVE-2021-24727
Block and Stop Bad Bots < 6.60 - Authenticated SQL Injections
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.7%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
13 Sep 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The StopBadBots WordPress plugin before 6.60 did not validate or escape the order and orderby GET parameter in some of its admin dashboard pages, leading to Authenticated SQL Injections
Affected products
Unknown · WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBotsWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →