Speed Booster Pack <= 4.3.3 - Admin+ SQL Injection
high
The Speed Booster Pack ⚡ PageSpeed Optimization Suite WordPress plugin before 4.3.3.1 does not escape the sbp_convert_table_name parameter before using it in a SQL statement to convert the related table, leading to an SQL injection
- CVSS:
- 7.2
- Affected:
- up to 4.3.3
- Fixed in:
- 4.3.3.1
- Disclosed:
- Oct 16, 2021
CVE-2021-25023 on NVD →
Speed Booster Pack PageSpeed Optimization Suite <= 4.1.9. - Authenticated (Admin+) Remote Code Execution
high
The Speed Booster Pack PageSpeed Optimization Suite WordPress plugin before 4.2.0 did not validate its caching_exclude_urls and caching_include_query_strings settings before outputting them in a PHP file, which could lead to RCE
- CVSS:
- 7.2
- Affected:
- up to 4.2.0
- Fixed in:
- 4.2.0
- Disclosed:
- Jul 5, 2021
CVE-2021-24430 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database