CVE-2023-1020
Steveas WP Live Chat Shoutbox <= 1.4.2 - Unauthenticated SQLi
Record summary
CVE-2023-1020 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 27, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 4, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Steveas WP Live Chat ShoutboxDefault status: affected | CVE List | Through 1.4.2 | affected |
wp_live_chat_shoutboxBrowse wp_live_chat_shoutbox_project / wp_live_chat_shoutbox | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALSteveas WP Live Chat Shoutbox <= 1.4.2 - SQL InjectionCVSS 9.8
The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
Impact
Unauthenticated attackers can execute SQL injection through AJAX actions to extract the complete WordPress database including chat logs and user credentials.
Remediation
Update to the latest version of the Steveas WP Live Chat Shoutbox plugin (1.4.2) or apply the vendor-provided patch to fix the SQL Injection vulnerability.
Source: ProjectDiscovery