AnalyticsWP <= 2.0.0 - Unauthenticated SQL Injection

Strategic Overview

Status
Patched in 2.1.0
Affected PluginAnalyticsWP
Affected Version<= 2.0.0
CVSS7.5High
CVECVE-2024-13321
View all AnalyticsWP vulnerabilities

Vulnerability Overview

The AnalyticsWP plugin for WordPress is vulnerable to SQL Injection via the 'custom_sql' parameter in all versions up to, and including, 2.0.0 due to insufficient authorization checks on the handle_get_stats() function. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Technical Analysis

REMEDIATION: Update to version 2.1.0, or a newer patched version --- IDENTIFIER: CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')) The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C

AnalyticsWP <= 2.0.0 - Unauthenticated SQL Injection (CVE-2024-13321)