S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 3, 2024

CVE-2024-50498 Scanner

CVE-2024-50498 Scanner - Remote Code Execution (RCE) vulnerability in WP Query Console

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.3k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-50498
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Improper Control of Generation of Code ('Code Injection') vulnerability in Ajit Bohra WP Query Console wp-query-console allows Code Injection.This issue affects WP Query Console: from n/a through <= 1.0.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
WP Query Consoleby Ajit Bohra
0
wp_querey_tableby lubus
0
Updated Aug 22, 2026View on NVD →
Detail

WP Query Console is a plugin designed for WordPress environments, developed to allow users to execute and debug SQL queries directly through the WordPress interface. It is often used by website administrators and developers for quick database checks and debugging. The plugin simplifies database management and enables dynamic queries, making it a popular choice for WordPress sites that require in-depth database interaction.

The vulnerability stems from improper control over the generation of executable code, allowing attackers to inject and execute arbitrary PHP code remotely. This type of vulnerability occurs when the system does not validate input adequately, enabling malicious payloads. The affected versions, up to and including 1.0, do not implement sufficient safeguards to prevent such exploits.

Technical details reveal that the endpoint `/wqc/v1/query` is exploitable via crafted HTTP POST requests. Attackers can specify the `queryArgs` parameter with malicious code, which the plugin executes without validation. The response, indicative of successful execution, includes detailed PHP information.

Exploitation of this vulnerability can lead to complete system compromise, allowing attackers to execute arbitrary commands, access sensitive data, or disrupt services. Since the vulnerability can be exploited without authentication, it poses a significant risk to unpatched systems.

REFERENCES

Solution Advice
  • Update the WP Query Console plugin to the latest patched version immediately.
  • Disable or remove the plugin if it is not actively used on the site.
  • Use a Web Application Firewall (WAF) to block malicious requests targeting the vulnerable endpoint.
  • Regularly monitor server logs for unusual activity or exploitation attempts.
  • Implement strict access controls to prevent unauthorized plugin modifications.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.