Home About Services Projects Blog Contact Policy
Vulnerability

Critical SQL Injection
Exposes 250k Sites

EA

Author

Eslam Abdullah

Date

Severity

9.8 Critical

SQL injection vulnerability in a WordPress plugin

A high-severity flaw in the "Ally" WordPress plugin has put sensitive data at risk for a quarter-million sites. Security researchers discovered that the plugin's search filtering mechanism failed to properly sanitize user input, allowing for a classic SQL Injection (SQLi) attack.

The Vulnerability

The vulnerability exists in the way the plugin handles AJAX requests for dynamic content loading. By injecting specific SQL commands into the `query_params` field, an unauthenticated attacker could extract information from the database, including user credentials, password hashes, and sensitive configuration data.

"SQL Injection remains one of the most dangerous and common vulnerabilities in web applications. It's a reminder that even popular plugins can have fundamental security flaws if not audited correctly," Eslam notes.

Impact

With over 246,000 active installations, the "Ally" plugin is a staple for many business and portfolio websites. The potential for mass exploitation is high, as the exploit is relatively easy to execute using automated tools.

  • Unauthenticated access to database records.
  • Extraction of WordPress admin password hashes.
  • Potential for full site takeover and data theft.

The Fix

The developers of "Ally" have released version 3.4.2 which addresses this vulnerability. All users are urged to update their plugins immediately. If you cannot update, it is recommended to disable the plugin until a patch can be applied.