S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jun 10, 2024

CVE-2024-3495 Scanner

CVE-2024-3495 scanner - SQL Injection vulnerability in Wordpress Country State City Dropdown CF7 plugin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.4k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-3495
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Country State City Dropdown CF7 plugin for WordPress is vulnerable to SQL Injection via the ‘cnt’ and 'sid' parameters in versions up to, and including, 2.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Country State City Dropdown CF7by trustyplugins
0
Updated Aug 22, 2026View on NVD →
Detail

The Country State City Dropdown CF7 plugin is used in WordPress sites to provide a cascading dropdown menu for country, state, and city selection in forms. It is widely utilized by developers and site owners to enhance user experience in form submissions. The plugin is popular for its ease of use and integration with the Contact Form 7 plugin. It is employed in various industries, including e-commerce and service-oriented websites, to streamline address entry. The plugin aims to simplify the input process for users filling out forms.

The SQL Injection vulnerability in the Country State City Dropdown CF7 plugin allows attackers to manipulate SQL queries by exploiting insufficient input escaping and preparation. This can lead to unauthorized access and extraction of sensitive data from the database. The vulnerability affects the 'cnt' and 'sid' parameters in versions up to and including 2.7.2. Exploitation of this vulnerability requires no authentication, making it a critical security risk.

The Country State City Dropdown CF7 plugin has a SQL Injection vulnerability due to inadequate escaping and preparation of user-supplied input. Specifically, the 'cnt' and 'sid' parameters in AJAX requests are vulnerable. Attackers can inject malicious SQL queries via these parameters, leading to the execution of arbitrary SQL commands. The issue is present in the 'tc_csca_get_cities' function in the 'admin-ajax.php' file. This vulnerability can be exploited remotely without authentication, potentially compromising the entire database.

Exploitation of the SQL Injection vulnerability can lead to severe consequences, including unauthorized access to sensitive data, such as user credentials and personal information. Attackers may execute arbitrary SQL commands, leading to data manipulation or deletion. This could result in website defacement, data loss, or unauthorized administrative access. The overall security and integrity of the affected WordPress site could be significantly compromised.

Join S4E to protect your digital assets from critical vulnerabilities like SQL Injection. Our comprehensive Cyber Threat Exposure Management platform offers continuous monitoring and detailed reporting to keep your website secure. Benefit from automated vulnerability scanning, real-time alerts, and expert remediation guidance. Sign up now to safeguard your online presence and prevent potential security breaches.

References:

Solution Advice
  • Update the Country State City Dropdown CF7 plugin to the latest version.
  • Implement proper input validation and escaping for all user-supplied parameters.
  • Utilize prepared statements for SQL queries to prevent injection attacks.
  • Regularly audit and review the code for security vulnerabilities.
  • Monitor the website for unusual activity and potential exploitation attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.