CVE-2021-24791 Scanner

Detects 'SQL Injection (SQLi)' vulnerability in Header Footer Code Manager plugin for WordPress affects v. before 1.1.14.


CVE-2021-24791 Scanner Detail

Vulnerability Overview

CVE-2021-24791 allows authenticated attackers (with admin privileges) to execute SQL injections in the Header Footer Code Manager plugin, potentially leading to data exposure or unauthorized database modifications.

Vulnerability Details

The flaw is found in the handling of the "orderby" and "order" request parameters in the plugin's Snippets admin dashboard. By manipulating these parameters, an attacker can inject and execute arbitrary SQL commands, leading to unauthorized data access or manipulation.

Possible Effects

Exploitation of CVE-2021-24791 can lead to:

  • Unauthorized access to sensitive WordPress database information.
  • Modification or deletion of database content, potentially causing website malfunction or data loss.
  • Escalation of privileges within the WordPress environment.

