Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-0769 PoC — WordPress plugin Users Ultra SQL注入漏洞

Source
Associated Vulnerability
Title:WordPress plugin Users Ultra SQL注入漏洞 (CVE-2022-0769)
Description:WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress plugin是一个应用插件。 WordPress plugin Users Ultra 3.1.0版本及之前版本存在SQL注入漏洞,该漏洞源于无法正确清理和转义data_target参数,将其插入SQL语句中,通过rating_vote AJAX操作执行,从而导致SQL注入。
Description
The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it is being interpolated in an SQL statement and then executed via the rating_vote AJAX action (available to both unauthenticated and authenticated users), leading to an SQL Injection.
File Snapshot

id: CVE-2022-0769 info: name: Users Ultra <= 3.1.0 - SQL Injection author: theamanrawat sever ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.