Lucene search

K
wpexploitRyan DewhurstWPEX-ID:1A9EF922-81D7-4CAA-AB9D-04F21E8B68F1
HistoryAug 26, 2018 - 12:00 a.m.

Gift Voucher <= 4.1.1 - Unauthenticated Blind SQL Injection

2018-08-2600:00:00
Ryan Dewhurst
10

0.01 Low

EPSS

Percentile

83.9%

The wpgv_doajax_front_template AJAX action (both authenticated and unauthenticated, defined in the front.php) does not sanitised, validate or escape the template_id parameter before using it in a SQL statement, leading to a SQL Injection issue. This has been present since at least 1.0.5 v4.1.0 tried to sanitise user input with sanitize_text_field() which is not sufficient.

The PoC will be displayed once the issue has been remediated

0.01 Low

EPSS

Percentile

83.9%

Related for WPEX-ID:1A9EF922-81D7-4CAA-AB9D-04F21E8B68F1