WordPress Plugin Vulnerabilities
AccessPress Social Icons < 1.6.8 - Authenticated SQL Injections
Description
During the security analysis, ThunderScan discovered SQL injection vulnerabilities in AccessPress Social Icons WordPress plugin. The easiest way to reproduce the vulnerability is to visit the provided URL while being logged in as administrator or another user that is authorized to access the plugin settings page. Any user with such privileges can obtain the valid _wpnonce value by previously visiting the settings page. Users that do not have full administrative privileges could abuse the database access the vulnerability provides to either escalate their privileges or obtain and modify database contents they were not supposed to be able to.
Proof of Concept
Affects Plugins
References
Classification
Type
INJECTION
OWASP top 10
CVSS
Miscellaneous
Original Researcher
Neven Biruski
Submitter
ethicalhack3r
Submitter twitter
Verified
No
WPVDB ID
Timeline
Publicly Published
2017-04-19 (about 8 years ago)
Added
2017-04-20 (about 8 years ago)
Last Updated
2020-08-24 (about 5 years ago)