Custom Permalinks <= 1.1 - Authenticated SQL Injection



Description
Missing checking of user controllable input during Bulk Action in the Custom Permalinks backend page leads to SQL injection vulnerability. 
Proof of Concept
Send authenticated POST request to "URL/wp-admin/admin.php?page=custom-permalinks-post-permalinks" with parameters "action=delete&permalinks[]=1) PAYLOAD -- "

Affects Plugin

fixed in version 1.2

Classification

Type SQLI
OWASP Top 10 A1: Injection
CWE CWE-89

Miscellaneous

Submitter Karim El Ouerghemmi
Submitter Website https://ripstech.com
Views 4354
Verified No
WPVDB ID 9029

Timeline

Publicly Published 2018-02-22 (over 1 year ago)
Added 2018-02-25 (over 1 year ago)
Last Updated 2018-02-25 (over 1 year ago)

Our Other Services

Online WordPress Vulnerability Scanner WPScan WordPress Security Plugin