Filtered by vendor Smartypantsplugins Subscriptions
Filtered by product Sp Rental Manager Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-38324 1 Smartypantsplugins 1 Sp Rental Manager 2021-09-22 7.5 High
The SP Rental Manager WordPress plugin is vulnerable to SQL Injection via the orderby parameter found in the ~/user/shortcodes.php file which allows attackers to retrieve information contained in a site's database, in versions up to and including 1.5.3.