Single Personal Message 1.0.3 WordPress Plugin SQL Injection
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 7.1epss 0.2%
exploitation probability
0.2%top 88% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Single Personal Message 1.0.3 contains an SQL injection vulnerability that allows authenticated users to execute arbitrary SQL queries by injecting malicious code through the message parameter. Attackers can access the admin interface and supply crafted SQL statements in the message parameter to extract sensitive database information including user credentials and site configuration data.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
Md. Shamim Shahnewaz · Single Personal Messagepublic PoCs found — 1
cve_referencewww.exploit-db.com/exploits/40870unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://lenonleite.com.br/https://wordpress.org/plugins/simple-personal-message/https://www.exploit-db.com/exploits/40870https://www.vulncheck.com/advisories/single-personal-message-wordpress-plugin-sql-injectionhttp://target/wp-admin/admin.php?page=simple-personal-message-outbox&action=view&message=0%20UNION%20SELECT%201,2.3,name,5,slug,7,8,9,10,11,12%20FROM%20wp_terms%20WHERE%20term_id=1