SP Rental Manager <= 1.5.3 Unauthenticated SQL Injection
Vulnerability Description
The SP Rental Manager WordPress plugin is vulnerable to SQL Injection via the orderby parameter found in the ~/user/shortcodes.php file which allows attackers to retrieve information contained in a site's database, in versions up to and including 1.5.3.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-38324
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- p7e4
Affected Vendor
SP Rental Manager
View all reports →