Record summary

CVE-2022-0787 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statements via AJAX actions (available to unauthenticated users), leading to SQL Injections

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Limit Login Attempts (Spam Protection)

CVE List5.1 to < 5.1affected

Nuclei templates

1
ProjectDiscoveryCRITICALLimit Login Attempts (Spam Protection) < 5.1 - SQL InjectionCVSS 9.8

The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statements via AJAX actions (available to unauthenticated users), leading to SQL Injections.

Impact

Unauthenticated attackers can execute time-based blind SQL injection via AJAX actions to extract database contents, potentially exposing WordPress user credentials and login attempt data.

Remediation

Fixed in version 5.1

WeaknessesCWE-89
Authorstheamanrawat
Template tagstime-based-sqlicvecve2022wpscansqliwordpresswp-pluginwpwp-limit-failed-login-attemptslimit_login_attempts_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:limit_login_attempts_project:limit_login_attempts:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2