wpDataTables < 3.4.2 - Blind SQL Injection via start Parameter
Vulnerability Description
The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user to perform Boolean-based blind SQL Injection in the table list page on the endpoint /wp-admin/admin-ajax.php?action=get_wdtable&table_id=1, on the 'start' HTTP POST parameter. This allows an attacker to access all the data in the database and obtain access to the WordPress application.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-24199
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Veno Eivazian, Massimiliano Ferraresi
References
More from wpDataTables
View All →Affected Vendor
wpDataTables
View all reports →