Lucene search

K
wpexploitKhanhWPEX-ID:02C5E10C-1AC7-447E-8AE5-B6D251BE750B
HistoryNov 02, 2020 - 12:00 a.m.

AccessPress Social Icons < 1.8.1 - Authenticated SQL Injection

2020-11-0200:00:00
khanh
381
accesspress social icons
sql injection
authenticated

EPSS

0.001

Percentile

37.0%

The plugin does not sanitise its widget attribute, allowing accounts with post permission, such as author, to perform SQL injections.

https://drive.google.com/file/d/1UBTpW3RcPR7iqTi94ueyXLwWH8aFHuoe/view?usp=sharing

Payload: [aps-social id="1 and sleep(3)"]

EPSS

0.001

Percentile

37.0%

Related for WPEX-ID:02C5E10C-1AC7-447E-8AE5-B6D251BE750B