S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Mar 8, 2024

CVE-2023-1408 Scanner

CVE-2023-1408 scanner - SQL Injection vulnerability in Video List Manager

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-1408
7.2
CVSShigh
Exploitable remotely over the internet · requires high privileges.

The Video List Manager WordPress plugin through 1.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

Attack Vector
Network
Privileges Req.
High
User Interaction
None
Affected
Video List Manager
0
Updated Aug 22, 2026View on NVD →
Detail

Video List Manager is a WordPress plugin that provides functionality to manage and display video lists on websites. It is typically used by website administrators and content creators who wish to organize videos into easily accessible lists for viewers. The plugin supports various video sources and offers customization options for the display of video lists, making it a versatile tool for enhancing website content with multimedia. This plugin is popular among websites that feature educational, tutorial, or entertainment video content.

The SQL Injection vulnerability in the Video List Manager plugin versions up to 1.7 is a critical security flaw that arises from the plugin's failure to properly sanitize and escape user inputs before using them in SQL statements. This vulnerability is exploitable by users with high privileges, such as administrators, allowing them to execute arbitrary SQL commands. SQL Injection attacks can lead to unauthorized access to the database, data leakage, and even full control over the website.

The issue is specifically related to how the plugin processes the 'videoID' parameter in certain admin pages. Without proper sanitization or escaping, an attacker with administrative access can inject malicious SQL code through this parameter. The exploitation of this vulnerability can result in unauthorized data manipulation or exfiltration, posing a significant risk to the confidentiality, integrity, and availability of the website's data.

Exploitation of this SQL Injection vulnerability could lead to unauthorized access to sensitive information stored in the website's database, manipulation or deletion of database content, and potentially compromising the entire WordPress site. This can have severe implications for website integrity, user privacy, and security, potentially leading to reputational damage and legal consequences for the site owners.

By utilizing the services provided by S4E, website owners can proactively identify and remediate vulnerabilities such as the SQL Injection in Video List Manager. Our platform offers comprehensive security scans that detect vulnerabilities early, providing detailed reports and remediation guidance. Membership on our platform ensures ongoing vigilance against security threats, helping to safeguard your digital assets and maintain the trust of your users.

 

References

Solution Advice
  1. Immediately update the Video List Manager plugin to the latest version, if available, that addresses this vulnerability.
  2. If no update is available, consider disabling or removing the plugin until a patch is released.
  3. Regularly update all WordPress components, including plugins, themes, and the core system, to their latest versions.
  4. Utilize web application firewalls (WAFs) and security plugins to monitor and potentially block malicious requests.
  5. Conduct regular security audits of your WordPress site to identify and address vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.