QID 150815
Date Published: 2024-03-01
QID 150815: WordPress Ultimate Member Plugin: SQL Injection Vulnerability (CVE-2024-1071)
Ultimate Member is a free user profile WordPress plugin that makes it easy to create powerful online communities and membership sites with WordPress.
Ultimate Member WordPress plugin is vulnerable to SQL Injection via the "sorting" parameter due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected Versions:
WordPress Ultimate Member Plugin before 2.8.3
QID Detection Logic:
This QID sends a HTTP GET request and checks for vulnerable version of WordPress plugin running on the target application.
Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary SQL queries on the target system.
CVEs related to QID 150815
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Ultimate Member |
|