Critical SQL Injection
Exposes 250k Sites
Author
Eslam Abdullah
Date
Severity
9.8 Critical
A high-severity flaw in the "Ally" WordPress plugin has put sensitive data at risk for a quarter-million sites. Security researchers discovered that the plugin's search filtering mechanism failed to properly sanitize user input, allowing for a classic SQL Injection (SQLi) attack.
The Vulnerability
The vulnerability exists in the way the plugin handles AJAX requests for dynamic content loading. By injecting specific SQL commands into the `query_params` field, an unauthenticated attacker could extract information from the database, including user credentials, password hashes, and sensitive configuration data.
Impact
With over 246,000 active installations, the "Ally" plugin is a staple for many business and portfolio websites. The potential for mass exploitation is high, as the exploit is relatively easy to execute using automated tools.
- Unauthenticated access to database records.
- Extraction of WordPress admin password hashes.
- Potential for full site takeover and data theft.
The Fix
The developers of "Ally" have released version 3.4.2 which addresses this vulnerability. All users are urged to update their plugins immediately. If you cannot update, it is recommended to disable the plugin until a patch can be applied.