Vulnerabilities > Mainwp > Mainwp Child Reports > 1.9.2

DATE CVE VULNERABILITY TITLE RISK
2021-10-18 CVE-2021-24754 SQL Injection vulnerability in Mainwp Child Reports
The MainWP Child Reports WordPress plugin before 2.0.8 does not validate or sanitise the order parameter before using it in a SQL statement in the admin dashboard, leading to an SQL injection issue
network
low complexity
mainwp CWE-89
6.5