PT-2023-16691 · WordPress · Intuitive Custom Post Order

Published

2023-06-09

·

Updated

2023-06-15

·

CVE-2023-1016

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Intuitive Custom Post Order plugin for WordPress versions up to, and including, 3.1.3
Description The issue arises from insufficient escaping on the user-supplied objects and tags parameters and a lack of sufficient preparation in the update options function as well as the refresh function, which runs queries on the same values. This allows authenticated attackers with administrator permissions to append additional SQL queries into already existing queries, potentially extracting sensitive information from the database. The attack's practicality may be limited to configurations where it is possible to bypass addslashes due to the database using a nonstandard character set, such as GBK.
Recommendations For versions up to, and including, 3.1.3, consider disabling the update options and refresh functions until a patch is available to prevent exploitation. Additionally, restrict access to the objects and tags parameters to minimize the risk of SQL injection attacks.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-1016

Affected Products

Intuitive Custom Post Order