S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2022-0747 Scanner

CVE-2022-0747 scanner - SQL Injection vulnerability in Infographic Maker iList

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0747
9.8
CVSS

The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it in a SQL statement via the qcld_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Infographic Maker – iList
AFFECTED< 4.3.8SAFE ✓≥ 4.3.8
Updated Aug 22, 2026View on NVD →
Detail

Infographic Maker iList is a WordPress plugin developed by QuantumCloud, designed for creating engaging infographics and lists directly within WordPress sites. It caters to bloggers, content creators, and marketers who aim to enhance their content's visual appeal and readability. The plugin offers a wide range of templates and customization options, allowing users to easily design and embed infographics into posts or pages. It's used widely across various industries to present data visually, making information easier to understand and share. The plugin integrates seamlessly with WordPress, making it accessible for users with minimal technical expertise.

The technical flaw resides in how the Infographic Maker iList plugin handles the post_id parameter within an AJAX request to the qcld_upvote_action. Specifically, the plugin fails to properly sanitize this parameter before including it in SQL queries executed against the website's database. As a result, an attacker can inject malicious SQL code into the post_id parameter to manipulate the database queries. This can lead to unauthorized access to sensitive information, manipulation of website data, or even database takeover. The vulnerability requires no authentication, making it particularly severe as it can be exploited by any user visiting the website.

Exploiting this SQL Injection vulnerability could lead to several adverse effects, including unauthorized access to sensitive data stored in the website's database, such as user credentials, personal information, and proprietary content. It can also enable attackers to insert fraudulent data, delete content, or manipulate existing data, potentially leading to website defacement or the dissemination of misleading information. In the worst-case scenario, attackers could gain administrative access to the WordPress site, allowing them to take complete control over the affected website.

By leveraging the security scanning capabilities of the S4E platform, users can proactively identify and mitigate vulnerabilities like the SQL Injection in Infographic Maker iList before they are exploited by malicious actors. Membership on our platform provides access to comprehensive vulnerability assessments, including this scanner, helping to safeguard digital assets against emerging threats. Our service enhances cybersecurity posture, minimizes the risk of data breaches, and ensures compliance with industry standards, offering peace of mind and a more secure online presence.

 

References

Solution Advice
  1. Update the Infographic Maker iList plugin to version 4.3.8 or later immediately.
  2. Regularly update all WordPress plugins and core files to their latest versions to protect against known vulnerabilities.
  3. Utilize web application firewalls (WAFs) to detect and prevent SQL Injection attacks.
  4. Implement strong input validation and parameterized queries to mitigate the risk of SQL Injection vulnerabilities.
  5. Regularly conduct security audits and vulnerability assessments on your WordPress site to identify and rectify potential security issues.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-0747 scanner - SQL Injection vulnerability in Infographic Maker iList | S4E