Code Clone WordPress Plugin SQL Injection Vulnerability in SnippetId Parameter
Vulnerability
A time-based SQL injection vulnerability has been identified in the Code Clone plugin for WordPress, affecting all versions through 0.9. The issue arises from inadequate escaping of user-supplied data in the snippetId parameter, coupled with insufficient preparation of the SQL query. This vulnerability allows authenticated attackers with Administrator-level access to inject additional SQL commands into existing queries, potentially leading to the extraction of sensitive information from the database.
Impact
Exploitation of this vulnerability allows for time-based SQL injection, where an attacker can manipulate SQL queries to extract sensitive data from the database.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
