Futurio Extra <= 1.6.2 - Authenticated (Admin+) SQL Injection
Strategic Overview
- Status
- Patched in 1.6.3
- Affected Plugin
- Futurio Extra
- Affected Version
< 1.6.3- CVSS
- 7.2High
- Weakness type
- CWE-89 · Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- CVE
CVE-2021-25109
At a glance
CVE-2021-25109 is a high-severity Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in the Futurio Extra WordPress plugin, affecting versions < 1.6.3. It carries a CVSS score of 7.2 (reachable over the network; low attack complexity; high confidentiality, integrity, availability impact). Exploitation requires an authenticated account at Admin level or above. The issue is fixed in version 1.6.3; sites on affected versions should update now. Disclosed January 2022, reported by Jan w Oleju.
Vulnerability Overview
The Futurio Extra WordPress plugin before 1.6.3 is affected by a SQL Injection vulnerability that could be used by high privilege users to extract data from the database as well as used to perform Cross-Site Scripting (XSS) against logged in admins by making send open a malicious link.
Technical Analysis
The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no interaction from a victim user. A successful exploit has high impact on confidentiality, integrity, availability — full site compromise territory.
CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Reaching this weakness in Futurio Extra < 1.6.3 takes an account at Admin level or above. SQL injection happens when request data is concatenated into a query instead of being bound as a parameter, letting an attacker change the structure of the statement rather than just its values.
A working injection can read any table the database user can see, which on a WordPress install means user records, password hashes and session or API secrets stored in options. For Futurio Extra the fix is 1.6.3: builds < 1.6.3 are affected, anything from 1.6.3 onward is not.
Remediation
Update to version 1.6.3, or a newer patched version
How does WordSec protect against this?
An attacker needs Admin access first, so the firewall sees the attempt as traffic from a logged-in account: WordSec's web application firewall inspects request payloads before WordPress loads them. None of that substitutes for the fix: Futurio Extra 1.6.3 closes this, and updating the plugin is the step that ends it.
- Firewall
- Alerts
External References
Related records
Other vulnerabilities in Futurio Extra
- 6.4CVE-2024-53802: Futurio Extra <= 2.0.14 Stored Cross-Site Scripting
CVE-2024-53802 - 6.4CVE-2024-50446: Futurio Extra <= 2.0.11 Stored Cross-Site Scripting
CVE-2024-50446 - 6.4CVE-2024-5646: Futurio Extra <= 2.0.5 Stored Cross-Site Scripting
CVE-2024-5646 - 4.3CVE-2024-10695: Futurio Extra <= 2.0.13 Post Disclosure
CVE-2024-10695 - 4.3CVE-2023-40201: Futurio Extra <= 1.9.0 Cross-Site Request Forgery
CVE-2023-40201 - 4.3CVE-2023-40201: Futurio Extra <= 1.8.2 Cross-Site Request Forgery
CVE-2023-40201 - 4.3CVE-2021-25110: Futurio Extra <= 1.6.2 Info Disclosure
CVE-2021-25110
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C