S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2022-0769 Scanner

CVE-2022-0769 scanner - SQL Injection vulnerability in Users Ultra

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.4k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0769
9.8
CVSS

The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it is being interpolated in an SQL statement and then executed via the rating_vote AJAX action (available to both unauthenticated and authenticated users), leading to an SQL Injection.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin
3.1.0
Updated Aug 22, 2026View on NVD →
Detail

Users Ultra is a versatile WordPress plugin designed to enhance user management and community-building capabilities on WordPress sites. It offers a wide array of features, including user profiles, membership levels, social media integration, and custom fields, catering to the needs of community websites, membership sites, and any WordPress site requiring advanced user management. Developed by UsersUltra, this plugin is particularly popular among website administrators looking for comprehensive user management solutions. It allows for the creation of sophisticated user communities within WordPress, facilitating engagement and interaction among site members. The plugin is widely used across various types of websites, from small community forums to large membership-based services.

Specifically, the vulnerability is present in the way the plugin processes the data_target parameter within an SQL statement executed through the rating_vote AJAX action. The parameter is not sufficiently sanitized or escaped before being interpolated into the SQL query, allowing attackers to insert malicious SQL code. This can lead to SQL Injection attacks, where attackers could retrieve sensitive information from the database, modify database data, or even escalate privileges. The exploit does not require user authentication, making it particularly severe since it can be exploited by any user or bot that can send requests to the admin-ajax.php file of a WordPress site using this plugin.

Exploiting this SQL Injection vulnerability can have severe consequences, including unauthorized access to sensitive data such as user information, passwords, and personal data stored in the database. Attackers could also manipulate or delete data, disrupt the integrity of the website, or use the compromised site to launch further attacks against users. In the worst-case scenario, attackers could gain administrative access to the WordPress dashboard, allowing them to take complete control over the website, modify its content, or use it as part of a botnet for malicious activities.

Joining the S4E platform empowers you to proactively detect and address vulnerabilities like the SQL Injection in Users Ultra before they can be exploited. Our platform offers comprehensive scanning capabilities that uncover potential security weaknesses in your digital assets, helping you to maintain the integrity and security of your WordPress site. By becoming a member, you gain access to an extensive suite of tools designed to enhance your cyber threat exposure management. This includes regular updates on new vulnerabilities, personalized security recommendations, and access to expert support, ensuring your website remains secure against the evolving landscape of cyber threats.

 

References

Solution Advice
  1. Immediately update the Users Ultra plugin to version 3.1.0 or the latest version available to address this vulnerability.
  2. Regularly update all WordPress plugins, themes, and the core installation to their latest versions.
  3. Employ a web application firewall (WAF) to help detect and block SQL Injection attempts and other common web attacks.
  4. Consider using security plugins that provide additional protections against SQL Injection and other types of vulnerabilities.
  5. Regularly perform security audits and vulnerability assessments on your WordPress site to identify and mitigate potential security risks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.