PT-2022-14041 · WordPress · Amtythumb

Daniel Krohmer

+1

·

Published

2022-06-06

·

Updated

2022-06-15

·

CVE-2022-1683

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions amtyThumb WordPress plugin versions through 4.2.0
Description The issue is related to the amtyThumb WordPress plugin, which does not properly sanitise and escape a parameter before using it in a SQL statement via its shortcode. This leads to an SQL injection and can be exploited by any authenticated user, as they can execute shortcodes via an AJAX action.
Recommendations For versions through 4.2.0, update to a version that includes the necessary sanitisation and escaping of parameters in SQL statements to prevent SQL injection. As a temporary workaround, consider restricting access to the shortcode execution via AJAX actions to prevent exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-1683

Affected Products

Amtythumb