CVE-2021-24303

HIGH

The JiangQie Official Website Mini Program WordPress plugin before 1.1.1 does not escape or validate the id GET parameter before using it in SQL statements, leading to SQL injection issues

Affects 1 product across 1 vendor.

BCS6.66
CVSS 3.18.8
EPSS1.6%
Percentile73th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, low privileges required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-89: SQL Injection

Attacker inserts SQL commands into application queries through user-controlled input, allowing unauthorized database access.

Related Attack Patterns (CAPEC)
CAPEC-7 Blind SQL Injection
via CWE-89
CAPEC-108 Command Line Execution through SQL Injection
via CWE-89
CAPEC-109 Object Relational Mapping Injection
via CWE-89
CAPEC-110 SQL Injection through SOAP Parameter Tampering
via CWE-89
CAPEC-470 Expanding Control over the Operating System from the Database
via CWE-89
Show all 6
via CWE-89

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

The JiangQie Official Website Mini Program WordPress plugin before version 1.1.1 is vulnerable to SQL injection due to improper handling of the id GET parameter.

BSID: BS-2021-GLOBAL-228383-H • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2021-24303?
The JiangQie Official Website Mini Program WordPress plugin before version 1.1.1 is vulnerable to SQL injection due to improper handling of the id GET parameter.
What is the CVSS score for CVE-2021-24303?
CVE-2021-24303 has CVSS 8.8 (High). Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. EPSS: 1.6%.
Is CVE-2021-24303 actively exploited?
No confirmed active exploitation of CVE-2021-24303 as of 2026-05-30.
How do I remediate CVE-2021-24303?
Priority: IMMEDIATE.
What systems are affected by CVE-2021-24303?
CVE-2021-24303 affects: Jiangqie.
Vulnerability Details
CVE IDCVE-2021-24303
BSIDBS-2021-GLOBAL-228383-H BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Published2021-09-06
Last Modified2024-11-21
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

The JiangQie Official Website Mini Program WordPress plugin before 1.1.1 does not escape or validate the id GET parameter before using it in SQL statements, leading to SQL injection issues

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker can exploit this vulnerability by injecting malicious SQL code through the id GET parameter in requests to the affected plugin. This could lead to unauthorized data access, modification, or deletion.

Exploitation Likelihood: HIGH

Affected Products
VendorProductFixed Version
Jiangqie Official Website Mini Program
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 1783 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash5281e635eaf4994df88cf3891783c73d1e109235d8578fafc3dfab8f9047f090ac4cb2c2f88d558760080443d55e2089064872a0b9351217ba5759a1c280bc42
Related CVEs affecting Jiangqie
CVE-2024-49314 10.0 Unrestricted Upload of File with Dangerous Type vulnerability in jiangqie Jia... CVE-2025-30604 7.6 Improper Neutralization of Special Elements used in an SQL Command ('SQL Inje...
View all Jiangqie CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →