.. / CVE-2022-0784

Exploit for WordPress Title Experiments Free <9.0.1 - SQL Injection (CVE-2022-0784)

Description:

WordPress Title Experiments Free plugin before 9.0.1 contains a SQL injection vulnerability. The plugin does not sanitize and escape the id parameter before using it in a SQL statement via the wpex_titles AJAX action, available to unauthenticated users. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

Nuclei Template

View the template here CVE-2022-0784.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2022/CVE-2022-0784.yaml
Copy

References:

https://github.com/cyllective/CVEs
https://wpscan.com/vulnerability/6672b59f-14bc-4a22-9e0b-fcab4e01d97f
https://github.com/superlink996/chunqiuyunjingbachang
https://nvd.nist.gov/vuln/detail/CVE-2022-0784
https://wordpress.org/plugins/wp-experiments-free/