The plugin does not validate the order and orderby parameters before using them in a SQL statement, leading to a SQL Injection issue
https://example.ocm/wp-admin/options-general.php?page=acfe-options&orderby=1%20and%20sleep(0.02)%23
ZhongFu Su(JrXnm) of Wuhan University
ZhongFu Su(JrXnm) of Wuhan University
Yes
2021-12-24 (about 1 years ago)
2021-12-24 (about 1 years ago)
2022-09-26 (about 4 months ago)