wpDiscuz before 7.6.47 contains an SQL injection vulnerability in the getAllSubscriptions() function where string parameters lack proper quote escaping in SQL queries. Attackers can inject malicious SQL code through email, activation_key, subscription_date, and imported_from parameters to manipulate database queries and extract sensitive information.
Parameters passed to the getAllSubscriptions() function — including email, activation_key, subscription_date, and imported_from — are not properly escaped before being used in SQL queries. An attacker can inject malicious SQL code through any of these parameters, thereby manipulating the logic of queries executed on the database. Since the attack does not require authentication or user interaction, it can be carried out remotely over the network.
An attacker can extract sensitive data from the WordPress database, including user data, passwords, or configurations. Depending on database permissions, data modification or deletion is also possible, which could lead to complete takeover of the application.
The wpDiscuz plugin should be immediately updated to version 7.6.47 or newer. The update is available in the WordPress repository at wordpress.org/plugins/wpdiscuz/. Until the patch is applied, it is recommended to consider temporarily disabling the plugin or restricting access to subscription-handling endpoints at the Web Application Firewall (WAF) level.
WordPress wpDiscuz plugin (Gvectors) in versions before 7.6.47
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XGvectors Wpdiscuz
APPGvectors< 7.6.47
Related vulnerabilities
Authentication bypass w pluginie wpDiscuz dla WordPress (do wersji 7.6.24)
RCE poprzez nieautoryzowany upload plików PHP w wtyczce WordPress wpDiscuz
SQL injection w pluginie wpDiscuz dla WordPress (wersje ≤ 5.3.5)
wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users...
Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthent...