Record summary

CVE-2020-20300 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

SQL injection vulnerability in the wp_where function in WeiPHP 5.0.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 7, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALWeiPHP 5.0 - SQL InjectionCVSS 9.8

WeiPHP 5.0 contains a SQL injection vulnerability via the wp_where function. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.

Remediation

Upgrade to a patched version of WeiPHP or apply the vendor-supplied patch to fix the SQL Injection vulnerability.

WeaknessesCWE-89
Authorspikpikcu
Template tagscvecve2020weiphpsqlsqlivkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:weiphp:weiphp:5.0:*:*:*:*:*:*:*
Shodan: http.html:"WeiPHP5.0"
Shodan: http.html:"weiphp"
Shodan: http.html:"weiphp5.0"
FOFA: body="weiphp"
FOFA: body="weiphp5.0"

Source: ProjectDiscovery

References

2