SP Rental Manager <= 1.5.3 - Unauthenticated SQL Injection
highThe SP Rental Manager WordPress plugin is vulnerable to SQL Injection via the orderby parameter found in the ~/user/shortcodes.php file which allows attackers to retrieve information contained in a site's database, in versions up to and including 1.5.3.
- CVSS:
- 8.2
- Affected:
- up to 1.5.3
- Fix:
- No patched version reported
- Disclosed:
- Sep 8, 2021