Single Personal Message 1.0.3 WordPress Plugin SQL Injection
Vulnerability Description
Single Personal Message 1.0.3 contains an SQL injection vulnerability that allows authenticated users to execute arbitrary SQL queries by injecting malicious code through the message parameter. Attackers can access the admin interface and supply crafted SQL statements in the message parameter to extract sensitive database information including user credentials and site configuration data.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-20063
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Lenon Leite
References
- https://www.exploit-db.com/exploits/40870
- https://wordpress.org/plugins/simple-personal-message/
- http://lenonleite.com.br/
- http://target/wp-admin/admin.php?page=simple-personal-message-outbox&action=view&message=0%20UNION%20SELECT%201,2.3,name,5,slug,7,8,9,10,11,12%20FROM%20wp_terms%20WHERE%20term_id=1
- https://www.vulncheck.com/advisories/single-personal-message-wordpress-plugin-sql-injection
Affected Vendor
Md. Shamim Shahnewaz
View all reports →