S4E just found a critical-severity finding from cve-2022-27924 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Sep 24, 2024

CVE-2024-5765 Scanner

CVE-2024-5765 scanner - SQL Injection vulnerability in WpStickyBar

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-5765
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The WpStickyBar WordPress plugin through 2.1.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
WpStickyBar
0
wpstickybarby a17lab
0
Updated Aug 22, 2026View on NVD →
Detail

WpStickyBar is a WordPress plugin utilized by website owners to enhance user engagement with sticky bars and headers. It is widely used in various websites to showcase promotions or announcements. The plugin facilitates easy integration with WordPress environments, making it accessible for non-technical users. Developers and marketers leverage this tool to improve site interactivity and visibility. However, security vulnerabilities can compromise its effectiveness and user safety.

The SQL Injection vulnerability in WpStickyBar allows attackers to execute arbitrary SQL code through unauthenticated AJAX requests. This occurs due to inadequate sanitization and escaping of user inputs before they are processed in SQL statements. Such vulnerabilities can lead to unauthorized data access or manipulation. It highlights the importance of secure coding practices in plugin development.

The vulnerability specifically affects the admin-ajax.php endpoint, where the action=stickybar_display parameter is processed. When an attacker sends a crafted request, they can manipulate the banner_id parameter to inject SQL code. This allows them to execute a time-based blind SQL injection, effectively querying the database. Without proper input validation, the plugin becomes susceptible to SQL injection attacks.

If exploited, the SQL Injection vulnerability can allow attackers to extract sensitive data from the database, modify existing records, or even execute administrative commands. This could lead to data breaches, loss of user trust, and potential regulatory repercussions. Additionally, it may facilitate further attacks on the web application and its underlying infrastructure. Overall, the consequences can be severe and damaging.

By joining the S4E platform, you gain access to comprehensive scanning tools that continuously monitor your digital assets for vulnerabilities like SQL Injection. Our advanced detection capabilities empower you to proactively safeguard your website and protect your users' data. With personalized support and expert insights, you can ensure robust security for your applications. Don't leave your security to chance—become a member today and enhance your cyber resilience.

References:

Solution Advice
  • Regularly update the WpStickyBar plugin to the latest version.
  • Implement strict input validation and sanitization for all user inputs.
  • Use prepared statements or parameterized queries for database interactions.
  • Monitor logs for unusual activities or suspicious requests.
  • Conduct regular security audits to identify and address potential vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.