CVE Published: 10/01/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: WPScan |
Vendor: Unknown |
Product: RegistrationMagic – Custom Registration Forms, User Registration and User Login Plugin Status : PUBLISHED
CVE-2021-24862 Description
The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches, which could lead to a SQL injection issue