WordPress Plugin Vulnerabilities

Translatepress Multilinugal < 2.3.3 - Admin+ SQLi

Description

The plugin is vulnerable to an authenticated SQL injection. By adding a new language (via the settings page) containing specific special characters, the backticks in the SQL query can be surpassed and a time-based blind payload can be injected.

Proof of Concept

Affects Plugins

References

Classification

Type
SQLI
OWASP top 10
CWE

Miscellaneous

Original Researcher
Elias Hohl
Submitter
Elias Hohl
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2022-07-23 (about 3 years ago)
Added
2022-09-06 (about 3 years ago)
Last Updated
2022-09-06 (about 3 years ago)

Other