PT-2024-18469 · WordPress · Wpvivid
Denis Werner
·
Published
2024-02-29
·
Updated
2025-01-16
·
CVE-2024-1981
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Migration, Backup, Staging – WPvivid plugin for WordPress version 0.9.68
Description
The issue arises from insufficient escaping on the user-supplied
table prefix parameter and lack of sufficient preparation on the existing SQL query, making it possible for unauthenticated attackers to append additional SQL queries into already existing queries. This can be used to extract sensitive information from the database.Recommendations
For version 0.9.68, consider disabling the
table prefix parameter until a patch is available to prevent SQL injection attacks. Restrict access to sensitive database information to minimize the risk of exploitation. Avoid using the table prefix parameter in existing SQL queries until the issue is resolved.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wpvivid