CRITICAL

CVE-2021-24915

CVSS v3

9.8

CRITICAL

EPSS Score

83.6%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated to perform SQL injections attacks, as well as get the list of all users registered on the blog, including their username and email address

Technical details

Published
11/29/2021

Frequently asked questions

What is CVE-2021-24915?

The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated to perform SQL injections attacks, as well as get the list of all users registered on the blog, including their username and email address

Is CVE-2021-24915 actively exploited?

Active exploitation of CVE-2021-24915 has not been confirmed. The EPSS score is 83.6%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-24915?

CVE-2021-24915 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2021-24915 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.