Users Ultra Membership Plugin <= 1.5.63 - Authenticated Blind SQL Injection
Strategic Overview
< 1.5.64CVE-2015-9395Vulnerability Overview
The users-ultra plugin before 1.5.64 for WordPress has SQL Injection via ajax actions, by exploiting following WP ajax actions SQL injections attacks can be performed: `edit_video`, `delete_photo`, `delete_gallery`, `delete_video`, `reload_photos`, `edit_gallery`, `edit_gallery_confirm`, `edit_photo`, `edit_photo_confirm`, `edit_video_confirm`, `set_as_main_photo`, `sort_photo_list`,`sort_gallery_list`, `reload_videos` via the following parameters: `video_id`, `photo_id`, `gal_id`, `order`
Technical Analysis
REMEDIATION: Update to version 1.5.64, or a newer patched version --- IDENTIFIER: CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')) The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C