CVE-2021-47941

HIGH

WordPress Plugin Survey & Poll 1.5.7.3 SQL Injection via sss_params

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-47941. PoCs published by Mohin Paramasivam.

AI-analyzed exploit summary This Python script exploits a SQL injection vulnerability in the WordPress Plugin Survey & Poll 1.5.7.3 by injecting malicious payloads into the 'wp_sap' cookie. It automates the extraction of database information, including version, hostname, user, and table data.

Description

WordPress Plugin Survey & Poll 1.5.7.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wp_sap cookie parameter. Attackers can craft SQL payloads in the cookie to extract sensitive database information including usernames, passwords, and other confidential data from the WordPress database.

Exploits (1)

exploitdb WORKING POC
by Mohin Paramasivam · pythonwebappsphp
https://www.exploit-db.com/exploits/50269

This Python script exploits a SQL injection vulnerability in the WordPress Plugin Survey & Poll 1.5.7.3 by injecting malicious payloads into the 'wp_sap' cookie. It automates the extraction of database information, including version, hostname, user, and table data.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: WordPress Plugin Survey & Poll 1.5.7.3
No auth needed
Prerequisites: Target URL with vulnerable plugin installed
devstral-2 · analyzed May 10, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit
ExploitDB-50269
https://www.exploit-db.com/exploits/50269
Product product
Official Product Homepage
http://modalsurvey.pantherius.com/
Third Party Advisory third-party-advisory
VulnCheck Advisory: WordPress Plugin Survey & Poll 1.5.7.3 SQL Injection via sss_params
https://www.vulncheck.com/advisories/wordpress-plugin-survey-poll-sql-injection-via-sss-params

Scores

CVSS v3 8.2
EPSS 0.0028
EPSS Percentile 19.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
Modalsurvey/Survey & Poll 1.5.7.3
Published May 10, 2026
Tracked Since May 10, 2026