plugin

Schreikasten Vulnerabilities

1 known security issue reported for the Schreikasten WordPress plugin. Most recent disclosed Oct 7, 2021.

1 high

Running Schreikasten on your site? Check whether your installed version is affected.

Scan your site free

Schreikasten <= 0.14.18 - Authenticated (Author+) SQL Injection

high

The Schreikasten WordPress plugin through 0.14.18 does not sanitise or escape the id GET parameter before using it in SQL statements in the comments dashboard from various actions, leading to authenticated SQL Injections which can be exploited by users as low as author

CVSS:
8.8
Affected:
up to 0.14.18
Fix:
No patched version reported
Disclosed:
Oct 7, 2021

CVE-2021-24630 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database