Vulnerabilities > Smartypantsplugins > SP Rental Manager
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-09-09 | CVE-2021-38324 | SQL Injection vulnerability in Smartypantsplugins SP Rental Manager 1.5.3 The SP Rental Manager WordPress plugin is vulnerable to SQL Injection via the orderby parameter found in the ~/user/shortcodes.php file which allows attackers to retrieve information contained in a site's database, in versions up to and including 1.5.3. | 7.5 |