ArielBrailovsky ViralAd WordPress Plugin SQL Injection Vulnerability
Vulnerability
A SQL injection vulnerability has been identified in the ArielBrailovsky-ViralAd plugin for WordPress, affecting all versions through 1.0.8. The issue arises in the printResultAndDie() function, where the 'id' parameter is inadequately sanitized, allowing unauthenticated attackers to inject additional SQL queries. This exploitation could lead to the unauthorized extraction of sensitive database information. Notably, the vulnerability seems to be exploitable only on very old WordPress versions.
Impact
Exploitation of this vulnerability allows for SQL injection, where an attacker can manipulate SQL queries to extract sensitive information from the database.
Remediation
No known patch is available for this vulnerability. Users are advised to review the vulnerability details and consider uninstalling the affected plugin.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
