cve/2021/CVE-2021-39351.md
2025-09-29 21:09:30 +02:00

866 B

CVE-2021-39351

Description

The WP Bannerize WordPress plugin is vulnerable to authenticated SQL injection via the id parameter found in the ~/Classes/wpBannerizeAdmin.php file which allows attackers to exfiltrate sensitive information from vulnerable sites. This issue affects versions 2.0.0 - 4.0.2.

POC

Reference

Github