QID 730530
Date Published: 2022-06-24
QID 730530: WordPress Plugin Stop Bad Bots SQL Injection Vulnerability
Stop Bad Bots, SPAM bots, Crawlers and spiders without DNS Cloud or API (EndPoint) Traffic Redirection and without slow down your site.
CVE-2022-0949: The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 6.930 does not properly sanitise and escape the fingerprint parameter before using it in a SQL statement via the stopbadbots_grava_fingerprint AJAX action, available to unauthenticated users, leading to a SQL injection.
Affected Versions:
Stop bad bots Plugin versions prior to 6.930
QID Detection Logic:(Unauthenticated)
This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the Elementor plugin.
Successful exploitation of this vulnerability may allow an unauthenticated attacker to execute arbitrary SQL queries on the target system.
- Stopbadbots Release Notes -
wordpress.org/plugins/stopbadbots/advanced/
CVEs related to QID 730530
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Stopbadbots Release Notes |
|