.. / CVE-2020-11530

Exploit for WordPress Chop Slider 3 - Blind SQL Injection (CVE-2020-11530)

Description:

WordPress Chop Slider 3 plugin contains a blind SQL injection vulnerability via the id GET parameter supplied to get_script/index.php. The plugin can allow an attacker to execute arbitrary SQL queries in the context of the WP database user, thereby making it possible to obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

Nuclei Template

View the template here CVE-2020-11530.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2020/CVE-2020-11530.yaml
Copy

References:

https://idangero.us/
http://seclists.org/fulldisclosure/2020/May/26
https://github.com/idangerous/plugins/tree/master/Chop%20Slider%203/Chop%20Slider%203%20Wordpress
https://wpscan.com/vulnerability/f10cd7d7-6a31-48e5-994c-b100c846001a
https://nvd.nist.gov/vuln/detail/CVE-2020-11530