S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2022-4117 Scanner

CVE-2022-4117 scanner - SQL Injection vulnerability in WordPress IWS Geo Form Fields

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.8k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-4117
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The IWS WordPress plugin through 1.0 does not properly escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
IWS
0
Updated Aug 22, 2026View on NVD →
Detail

The WordPress IWS Geo Form Fields plugin is designed to enhance WordPress sites by providing geo-location form fields, such as country, state, and city selectors. It's typically used by websites requiring users to input geographical information, like e-commerce, event registration, and listings sites. This plugin is particularly useful for customizing user experience based on location, streamlining forms, and improving data accuracy in user submissions.

The SQL Injection vulnerability in the WordPress IWS Geo Form Fields plugin up to and including version 1.0 arises from the plugin's failure to properly sanitize user inputs before using them in SQL statements. This flaw permits unauthenticated attackers to execute arbitrary SQL commands via an AJAX action, potentially leading to unauthorized access to sensitive information, database manipulation, or site compromise.

Specifically, the vulnerability is triggered by improperly sanitized input in the 'country_id' parameter of an AJAX request handled by the 'iws_gff_fetch_states' action. By inserting specially crafted SQL code into this parameter, attackers can manipulate SQL queries executed by the plugin, leading to the execution of malicious SQL statements that can read, modify, or delete data in the WordPress database without authorization.

Successful exploitation of this SQL Injection could result in the compromise of sensitive data stored within the WordPress site's database, including user personal information, credentials, and site content. It could also allow attackers to perform unauthorized administrative actions or take control of the affected site, posing significant security risks to both the site and its users.

By becoming a member of the S4E platform, you gain access to advanced security scanning tools that can identify and help mitigate vulnerabilities like the SQL Injection in the WordPress IWS Geo Form Fields plugin. Our service offers comprehensive security assessments, actionable recommendations, and continuous monitoring to protect your digital assets against evolving cyber threats. Enhance your site's security posture and protect against breaches with our expert support and cutting-edge technology.

 

References

Solution Advice
  1. Immediately update the WordPress IWS Geo Form Fields plugin to version 1.1 or higher, as this version contains a fix for the SQL Injection vulnerability.
  2. Regularly update all WordPress plugins and core software to their latest versions to address known vulnerabilities.
  3. Implement a web application firewall (WAF) to help detect and block SQL Injection attempts and other malicious activities.
  4. Employ robust input validation and sanitization techniques to prevent malicious data from affecting database queries.
  5. Conduct periodic security audits and vulnerability assessments to identify and remediate potential security issues promptly.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-4117 scanner - SQL Injection vulnerability in WordPress IWS Geo Form Fields | S4E