Vulnerabilities (CVE)

Filtered by vendor Smartypantsplugins Subscribe
Filtered by product Sp Rental Manager
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-38324 1 Smartypantsplugins 1 Sp Rental Manager 2024-11-21 5.0 MEDIUM 8.2 HIGH
The SP Rental Manager WordPress plugin is vulnerable to SQL Injection via the orderby parameter found in the ~/user/shortcodes.php file which allows attackers to retrieve information contained in a site's database, in versions up to and including 1.5.3.