Executive Summary

A SQL injection vulnerability was discovered in the SaveTo Wishlist Lite WordPress plugin before version 1.1.5. This vulnerability allows unauthenticated attackers to append additional SQL queries and extract sensitive information from the database. The vulnerability has a CVSS score of 8.6, indicating high severity.

Technical Analysis

The vulnerability is classified as a SQL injection (CWE-89) and is located in the ORDER BY clause of a SQL query. The SaveTo Wishlist Lite WordPress plugin does not properly sanitize and escape parameters before using them in the SQL query. This allows an unauthenticated attacker to inject malicious SQL code and extract sensitive information from the database.

How It Gets Exploited

An unauthenticated remote attacker can exploit this vulnerability by sending a crafted request to the vulnerable plugin. The attacker would send a request with a malicious parameter that is not properly sanitized or escaped, allowing the attacker to inject additional SQL queries. For example, an attacker could send a request with a parameter that contains a malicious SQL query, such as a UNION operator or a subquery. The plugin would then execute the malicious query, allowing the attacker to extract sensitive information from the database.

Impact Assessment

The vulnerability affects the SaveTo Wishlist Lite WordPress plugin before version 1.1.5. An attacker can achieve high confidentiality impact, allowing them to extract sensitive information from the database. The vulnerability has a CVSS score of 8.6, indicating high severity.

Recommended Actions

To mitigate this vulnerability, it is recommended to update the SaveTo Wishlist Lite WordPress plugin to version 1.1.5 or later. Additionally, users should ensure that their WordPress installation and plugins are up-to-date and patched regularly. Detection guidance: Monitor plugin version and update history; look for suspicious database queries or unusual traffic patterns.

Sources

- National Vulnerability Database (NVD) - WPScan