WordPress Code Clone Plugin SQL Injection Vulnerability in Snippets Management
The Code Clone plugin for WordPress contains a time-based SQL Injection vulnerability through the 'snippetId' parameter in versions up to and including 0.9. The issue stems from improper parameter escaping and inadequate SQL query preparation. Authenticated attackers possessing Administrator-level privileges can manipulate the parameter to append additional SQL queries. These modified queries enable potential extraction of sensitive information directly from the database, posing a significant security risk to WordPress sites using this plugin.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
allhart code clone |