← WordPress Vulnerabilities
WordPress security by component

WordPress支付宝Alipay|财付通Tenpay|贝宝PayPal集成插件

WordPress支付宝Alipay|财付通Tenpay|贝宝PayPal集成插件 is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Sep 06, 2021; the highest CVE/CNA score is 7.2.

Plugin slug: alipay

CVE-2021-24390: WordPress支付宝Alipay|财付通Tenpay|贝宝PayPal集成插件: SQL injection

WordPress支付宝Alipay|财付通Tenpay|贝宝PayPal集成插件 is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.

PublishedSep 06, 2021
Safe version guidanceSee mitigation notes
Safe version
Sep 06, 2021 CVE-2021-24390
WordPress支付宝Alipay|财付通Tenpay|贝宝PayPal集成插件: SQL injection
WordPress支付宝Alipay|财付通Tenpay|贝宝PayPal集成插件 is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.2
NVD7.2
Oct 21, 2014 CVE-2014-4514
Alipay: Cross-site scripting
Alipay is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.3
NVD4.3