S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2022-0773 Scanner

CVE-2022-0773 scanner - SQL Injection vulnerability in Documentor WordPress Plugin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0773
9.8
CVSS

The Documentor WordPress plugin through 1.5.3 fails to sanitize and escape user input before it is being interpolated in an SQL statement and then executed, leading to an SQL Injection exploitable by unauthenticated users.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Documentor – Create Product Documentation
1.5.3
Updated Aug 22, 2026View on NVD →
Detail

The Documentor WordPress plugin is a tool designed for creating and managing online documentation on WordPress websites. It is widely used by developers, content creators, and website administrators to provide users with guides, FAQs, and other types of documentation directly on their websites. The plugin offers features such as customizable skins, responsive design, and user-friendly interfaces to enhance the accessibility and appearance of the documentation. Being a WordPress plugin, it integrates seamlessly with the WordPress ecosystem, making it a convenient option for WordPress site owners. The vulnerability affects versions up to and including 1.5.3, highlighting the importance of keeping software up to date.

This SQL Injection vulnerability is specifically found in the way the Documentor plugin handles input within the `doc_search_results` AJAX action. Attackers can exploit this by sending specially crafted requests to the `admin-ajax.php` file, including malicious SQL code. The plugin does not sufficiently sanitize the `docid` parameter before it is used in SQL queries, allowing attackers to inject arbitrary SQL commands. This can lead to unauthorized data access or manipulation. The exploitation of this vulnerability does not require authentication, making it particularly severe.

Exploiting this vulnerability could have severe consequences for a WordPress site using the vulnerable versions of the Documentor plugin. Attackers can gain unauthorized access to the site's database, leading to the theft of sensitive information such as user credentials, personal data, and proprietary content. Additionally, attackers could manipulate or delete data, disrupting the site's operations and content integrity. This could harm the site's reputation, lead to financial losses, and potentially expose the site's owners to legal liabilities.

By joining the S4E platform, users can benefit from comprehensive digital asset monitoring and vulnerability detection, including the critical SQL Injection vulnerability in the Documentor WordPress plugin. Our platform's advanced scanning capabilities empower users to identify and address vulnerabilities before they can be exploited by attackers, enhancing the security posture of their digital presence. With timely notifications, detailed reports, and actionable insights, members can proactively manage their cybersecurity risks, ensuring their websites remain secure, compliant, and resilient against emerging threats.

 

References

Solution Advice
  1. Update to Documentor version 1.5.3 or later immediately to mitigate this vulnerability.
  2. Regularly update all WordPress plugins, themes, and the core to the latest versions.
  3. Implement website security best practices, such as using a web application firewall (WAF) and conducting regular security audits.
  4. Educate users and administrators on the importance of security hygiene and the potential risks associated with outdated software.
  5. Monitor your website for unusual activities or unauthorized access attempts, which could indicate exploitation attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.