Record summary

CVE-2018-16159 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

The Gift Vouchers plugin through 2.0.1 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/admin-ajax.php wpgv_doajax_front_template request.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 26, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

1

Catalogued exploits

ExploitDBWordPress Plugin Gift Voucher 1.0.5 - (Authenticated) 'template_id' SQL InjectionExploitDB exploitby Renos NikolaouNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALWordPress Gift Voucher <4.1.8 - Blind SQL InjectionCVSS 9.8

WordPress Gift Vouchers plugin before 4.1.8 contains a blind SQL injection vulnerability via the template_id parameter in a wp-admin/admin-ajax.php wpgv_doajax_front_template request. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

Impact

Successful exploitation of this vulnerability could allow an attacker to extract sensitive information from the database.

Remediation

Fixed in version 4.1.8.

WeaknessesCWE-89
Authorstheamanrawat
Template tagstime-based-sqlicvecve2018sqliwordpressunauthwpgift-voucheredbwpscanwp-plugincodemenschen
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:codemenschen:gift_vouchers:*:*:*:*:*:wordpress:*:*
Shodan: http.html:"/wp-content/plugins/gift-voucher/"
FOFA: body="/wp-content/plugins/gift-voucher/"

Source: ProjectDiscovery

References

3