CVE-2021-47941
HIGHWordPress Plugin Survey & Poll 1.5.7.3 SQL Injection via sss_params
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47941. PoCs published by Mohin Paramasivam.
AI-analyzed exploit summary This Python script exploits a SQL injection vulnerability in the WordPress Plugin Survey & Poll 1.5.7.3 by injecting malicious payloads into the 'wp_sap' cookie. It automates the extraction of database information, including version, hostname, user, and table data.
Description
WordPress Plugin Survey & Poll 1.5.7.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wp_sap cookie parameter. Attackers can craft SQL payloads in the cookie to extract sensitive database information including usernames, passwords, and other confidential data from the WordPress database.
Exploits (1)
This Python script exploits a SQL injection vulnerability in the WordPress Plugin Survey & Poll 1.5.7.3 by injecting malicious payloads into the 'wp_sap' cookie. It automates the extraction of database information, including version, hostname, user, and table data.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N