S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated May 6, 2024

CVE-2024-1071 Scanner

CVE-2024-1071 scanner - SQL Injection vulnerability in WordPress Ultimate Member

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.4k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-1071
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in versions 2.1.3 to 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Pluginby ultimatemember
2.1.3
registrationby ultimatemember
2.1.3
user_profileby ultimatemember
2.1.3
loginby ultimatemember
2.1.3
Updated Sep 10, 2026View on NVD →
Detail

WordPress Ultimate Member is a popular plugin utilized by WordPress website administrators for managing user profiles, registrations, logins, and content restrictions. It serves the purpose of creating member directories and controlling membership access on WordPress-based platforms. However, versions 2.1.3 to 2.8.2 of the plugin are vulnerable to SQL Injection attacks due to insufficient sanitization of user-supplied input and inadequate preparation of SQL queries.

The vulnerability detected in WordPress Ultimate Member versions 2.1.3 to 2.8.2 involves SQL Injection, allowing unauthenticated attackers to manipulate SQL queries via the 'sorting' parameter. Due to improper input validation and lack of query preparation, attackers can inject malicious SQL code into existing queries, potentially leading to unauthorized access to sensitive database information.

The SQL Injection vulnerability in WordPress Ultimate Member is exploited by crafting malicious POST requests to the '/wp-admin/admin-ajax.php' endpoint with a payload appended to the 'sorting' parameter. By injecting SQL commands, such as sleep(), attackers can delay responses and extract sensitive data from the database. The lack of proper input sanitization and query preparation exacerbates the risk of successful exploitation.

Exploiting the SQL Injection vulnerability in WordPress Ultimate Member may lead to unauthorized access to sensitive user data stored in the WordPress database. Attackers can extract user credentials, personal information, and other sensitive data, compromising the confidentiality and integrity of user accounts. Furthermore, the exploitation can facilitate further attacks, such as privilege escalation or credential theft.

Safeguard your WordPress website from SQL Injection vulnerabilities and protect sensitive user data by leveraging the comprehensive security scanning capabilities offered by the S4E platform. Join our platform to proactively identify and remediate vulnerabilities like CVE-2024-1071, ensuring the integrity of your WordPress site and the security of your users' information.

 

References:

Solution Advice
  • Upgrade WordPress Ultimate Member plugin to version 2.8.3 or later to mitigate the SQL Injection vulnerability.
  • Implement input validation and parameterized queries to sanitize user-supplied input and prevent SQL Injection attacks.
  • Regularly monitor and audit web application logs for suspicious activities, including unusual database queries or errors indicating potential exploitation attempts.
  • Educate website administrators and developers on secure coding practices, emphasizing the importance of input validation and SQL query preparation to prevent injection vulnerabilities.
  • Consider implementing web application firewalls (WAFs) or intrusion detection systems (IDS) to detect and block malicious SQL Injection attempts targeting WordPress websites.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-1071 scanner - SQL Injection vulnerability in WordPress Ultimate Member | S4E