vendor:
Accesspress Social Icons
by:
Nguyen Khang
8.8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Accesspress Social Icons
Affected Version From: <= 1.7.9
Affected Version To: <= 1.7.9
Patch Exists: YES
Related CWE: N/A
CPE: 2.3:a:accesspressthemes:accesspress_social_icons:1.7.9
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 18.04
2020
WordPress Theme Accesspress Social Icons 1.7.9 – SQL injection (Authenticated)
A blind SQL injection vulnerability is present in Ajax load more. An attacker can send a malicious POST request with a crafted payload to the vulnerable parameter 'id' in order to execute arbitrary SQL queries.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in SQL queries.