CVE-2021-24928 Information

Description

The Rearrange Woocommerce Products WordPress plugin before 3.0.8 does not have proper access controls in the save_all_order AJAX action nor validation and escaping when inserting user data in SQL statement leading to an SQL injection and allowing any authenticated user such as subscriber to modify arbitrary post content (for example with an XSS payload) as well as exfiltrate any data by copying it to another post.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Reference

https://wpscan.com/vulnerability/3762a77c-b8c9-428f-877c-bbfd7958e7be

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

HIGH

Base Score

NONE

Base Severity

6.5

Share on: