Record summary

CVE-2023-1020 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 27, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 4, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Steveas WP Live Chat Shoutbox

Default status: affected

CVE ListThrough 1.4.2affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALSteveas WP Live Chat Shoutbox <= 1.4.2 - SQL InjectionCVSS 9.8

The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

Impact

Unauthenticated attackers can execute SQL injection through AJAX actions to extract the complete WordPress database including chat logs and user credentials.

Remediation

Update to the latest version of the Steveas WP Live Chat Shoutbox plugin (1.4.2) or apply the vendor-provided patch to fix the SQL Injection vulnerability.

WeaknessesCWE-89
Authorstheamanrawat
Template tagscve2023cvewpscansqliwordpresswp-pluginwpwp-shoutbox-live-chatwp_live_chat_shoutbox_projectvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:wp_live_chat_shoutbox_project:wp_live_chat_shoutbox:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2