Code Clone WordPress Plugin SQL Injection Vulnerability in SnippetId Parameter

Vulnerability

A time-based SQL injection vulnerability has been identified in the Code Clone plugin for WordPress, affecting all versions through 0.9. The issue arises from inadequate escaping of user-supplied data in the snippetId parameter, coupled with insufficient preparation of the SQL query. This vulnerability allows authenticated attackers with Administrator-level access to inject additional SQL commands into existing queries, potentially leading to the extraction of sensitive information from the database.

Impact

Exploitation of this vulnerability allows for time-based SQL injection, where an attacker can manipulate SQL queries to extract sensitive data from the database.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.5
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.