AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-24337

HIGH · CVSS 8.8 EPSS 1.57%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-06-07 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.8. It affects WordPress. It involves a SQL injection risk.

CVE
CVE-2021-24337
Severity
HIGH
CVSS
8.8
EPSS
1.57%
WordPress

Original NVD Description

The id GET parameter of one of the Video Embed WordPress plugin through 1.0's page (available via forced browsing) is not sanitised, validated or escaped before being used in a SQL statement, allowing low privilege users, such as subscribers, to perform SQL injection.