CVE-2021-24666 Scanner

Detects 'SQL Injection (SQLi)' vulnerability in Podlove Podcast Publisher plugin for WordPress affects v. before 3.5.6.


Vulnerability Overview

CVE-2021-24666 allows unauthenticated attackers to perform SQL injections through vulnerable REST routes provided by the Social & Donations module in the Podlove Podcast Publisher plugin, potentially leading to sensitive data exposure or unauthorized database modifications.

Vulnerability Details

The vulnerability originates from the plugin's inability to properly sanitize the 'id' and 'category' parameters in the /services/contributor/(?P<id>[\d]+) REST route. An attacker can exploit this flaw to execute arbitrary SQL commands, leading to unauthorized access to the database or manipulation of its contents.

Possible Effects

If exploited, CVE-2021-24666 could result in:

  • Unauthorized access to sensitive information stored in the WordPress database.
  • Modification or deletion of critical data leading to website defacement or downtime.
  • Potential escalation of privileges allowing further exploitation of the WordPress site.

