Record summary

CVE-2023-3077 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The MStore API WordPress plugin before 3.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to a Blind SQL injection exploitable by unauthenticated users. This is only exploitable if the site owner elected to pay to get access to the plugins' pro features, and uses the woocommerce-appointments plugin.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 12, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

MStore API

Default status: unaffected

CVE ListBefore 3.9.8affected

Nuclei templates

1
ProjectDiscoveryCRITICALMStore API < 3.9.8 - SQL InjectionCVSS 9.8

The MStore API WordPress plugin before 3.9.8 is vulnerable to Blind SQL injection via the product_id parameter.

Impact

Allows an attacker to extract sensitive data from the database

Remediation

Update MStore API WordPress Plugin to the latest version to mitigate the vulnerability

AuthorsDhiyaneshDK
Template tagstime-based-sqlicvecve2023wpscanwordpresswp-pluginwpmstore-apisqliinspireuivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:inspireui:mstore_api:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/mstore-api/
FOFA: body=/wp-content/plugins/mstore-api/

Source: ProjectDiscovery

References

2