Record summary

CVE-2020-13640 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoadMoreComments request. (No 7.x versions are affected.)

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 6, 2020 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

1

Repository PoCs

GitHubasterite3/CVE-2020-13640Repository PoCby asterite3Stars: 1Not analyzed1 file

3.1 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALwpDiscuz <= 5.3.5 - SQL InjectionCVSS 9.8

A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoadMoreComments request.

Impact

Unauthenticated attackers can execute arbitrary SQL commands to extract database contents including user credentials, posts, and sensitive WordPress configuration data.

Remediation

Upgrade to wpDiscuz version 5.3.6 or later.

WeaknessesCWE-89
AuthorsSourabh-Sahu
Template tagscvecve2020wordpresswpwp-pluginwpdiscuzsqlivkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:gvectors:wpdiscuz:*:*:*:*:*:wordpress:*:*
FOFA: body="/wp-content/plugins/wpdiscuz"

Source: ProjectDiscovery

References

6