CVE-2020-37244: WordPress Plugin Supsystic Membership 1.4.7 SQL Injection via sidx
Supsystic Membership 1.4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'search' and 'sidx' parameters. Attackers can send GET requests to the badges module with crafted payloads to extract sensitive database information using time-based blind or UNION-based SQL injection techniques.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-37244?
CVE-2020-37244 has a high severity rating due to its potential for SQL injection attacks by unauthenticated users.
How do I fix CVE-2020-37244?
To fix CVE-2020-37244, update the Supsystic Membership plugin to version 1.4.8 or later.
What are the affected versions for CVE-2020-37244?
CVE-2020-37244 affects the Supsystic Membership plugin version 1.4.7.
What impact does CVE-2020-37244 have on my website?
CVE-2020-37244 allows attackers to execute arbitrary SQL commands, which can lead to data exposure or compromise.
Who is vulnerable to CVE-2020-37244?
Any WordPress site using the Supsystic Membership plugin version 1.4.7 is vulnerable to CVE-2020-37244.