Description
The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the -order- parameter of the /wp-json/wp/v3/post/list REST endpoint in versions up to and including 1.8. This is due to insufficient escaping on the user-supplied -order- parameter (read directly from $_GET[-order-] into $shorting) and the lack of sufficient preparation on the existing SQL query in the listPost() function, where the value is concatenated unquoted into the ORDER BY clause and executed via $wpdb->get_results() without $wpdb->prepare(). The endpoint is registered with permission_callback -__return_true- and performs only a broken header-based check that validates the supplied -Username- corresponds to an administrator account while never verifying the -Password-. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
- Publication
- 2026-06-24 07:16:29
- Versions concernées
- <=1.8
- Type
- Application web
- Vecteur
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N