Mail Mint
- <= 1.24.2
A time-based SQL injection vulnerability has been identified in the Mail Mint WordPress plugin, specifically in versions through 1.24.2. The issue arises in the 'contact_ids' parameter, where insufficient escaping of user-supplied data allows authenticated attackers with administrator-level access to append malicious SQL queries. This exploitation could lead to the extraction of sensitive information from the database.
Exploitation of this vulnerability allows for authenticated SQL injection, where an attacker can manipulate SQL queries to extract sensitive database information.
To reproduce this vulnerability, an authenticated user with administrator privileges can send a request to the WordPress REST API endpoint for contacts, including a crafted 'contact_ids' parameter that exploits the SQL injection flaw. The lack of proper input sanitization allows additional SQL commands to be executed, potentially leading to unauthorized data access.
Users are advised to update the Mail Mint WordPress plugin to version 1.24.3 or later, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.