.. / CVE-2021-24442

Exploit for Wordpress Polls Widget < 1.5.3 - SQL Injection (CVE-2021-24442)

Description:

The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL statement when sending a Poll result, allowing unauthenticated users to perform SQL Injection attacks

Nuclei Template

View the template here CVE-2021-24442.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-24442.yaml
Copy

References:

https://wpscan.com/vulnerability/7376666e-9b2a-4239-b11f-8544435b444a/
https://wordpress.org/plugins/polls-widget/
https://nvd.nist.gov/vuln/detail/CVE-2021-24442