Security Advisory

CVE-2021-24848

8.8
HIGH

Vulnerability Description

The mediamaticAjaxRenameCategory AJAX action of the Mediamatic WordPress plugin before 2.8.1, available to any authenticated user, does not sanitise the categoryID parameter before using it in a SQL statement, leading to an SQL injection
Published Date December 13, 2021
Official Source NIST NVD Advisory