S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2022-0827 Scanner

Detect SQLi in WordPress Best Books plugin (CVE-2022-0827) with 9.8 CVSS.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0827
9.8
CVSS

The Bestbooks WordPress plugin through 2.6.3 does not sanitise and escape some parameters before using them in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Bestbooks
2.6.3
Updated Aug 19, 2026View on NVD →
Detail

WordPress Best Books is a plugin tailored for WordPress sites, designed to manage and display book collections. It serves libraries, bookstores, and individual collectors by enabling them to showcase their books online in an organized and accessible manner. This plugin supports the categorization of books, provides detailed views of each book, and includes features for search and management within the WordPress dashboard. It is particularly useful for educational institutions, authors, and online retailers looking to promote literacy and accessibility to their collections. The plugin's integration with WordPress makes it a convenient choice for users already familiar with the WordPress ecosystem.

The technical flaw occurs within an AJAX action where specific parameters are not adequately sanitized and escaped before being included in a SQL query. This vulnerability is exploitable via the 'bestbooks_add_transaction' action, where the 'description', 'debit', and 'credit' parameters can be manipulated to inject malicious SQL code. Since the vulnerability can be exploited without authentication, it poses a significant risk, allowing attackers to manipulate database queries and access sensitive data. The exploitation of this flaw can lead to unauthorized administrative operations and data leakage from the affected site's database.

Exploitation of this SQL Injection vulnerability can have several adverse effects, including unauthorized access to sensitive data, such as user credentials and personal information. Attackers could modify or delete data within the database, leading to data loss or corruption. Additionally, this could facilitate further attacks, such as privilege escalation or lateral movement within the network. The integrity and availability of the affected website could be compromised, resulting in reputational damage and potential legal implications for failing to safeguard user data.

S4E offers a unique platform that enables users to comprehensively assess their digital assets for vulnerabilities like SQL Injection in the WordPress Best Books plugin. By becoming a member, you'll benefit from our advanced scanning technologies, which provide detailed vulnerability reports, remediation guidance, and prioritization based on severity. Our service ensures continuous monitoring and assessment of your digital environment, helping you maintain a robust security posture against emerging threats. Join us to protect your online presence and build trust with your users by demonstrating a commitment to security.

 

References

Solution Advice
  1. Update the WordPress Best Books plugin to version 2.6.4 or the latest version available immediately.
  2. Regularly update all WordPress plugins and themes to ensure security patches are applied.
  3. Implement a web application firewall (WAF) to help detect and block SQL injection attempts.
  4. Conduct regular security audits and vulnerability assessments to identify and mitigate potential vulnerabilities.
  5. Educate developers about secure coding practices, especially regarding input validation and sanitization to prevent similar vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.