Security Advisory

CVE-2021-39351

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-10-06 15:22:00
Last updated 2025-02-14 18:24:43
Assigner Wordfence
CVSS score not scored
State PUBLISHED

Description

The WP Bannerize WordPress plugin is vulnerable to authenticated SQL injection via the id parameter found in the ~/Classes/wpBannerizeAdmin.php file which allows attackers to exfiltrate sensitive information from vulnerable sites. This issue affects versions 2.0.0 - 4.0.2.