Security Research

CVE-2024-27956 WP Automatic SQL Injection: from 9.9 plugin bug to admin account takeover

#Vulnerability Analysis#Code Audit#Web Security
Dark dossier of WordPress plugin SQLi path and eviladmin takeover

The WordPress valvePress/Automatic plugin does not filter %0a or null bytes in the auth parameter. An attacker bypasses auth, runs SQL injection through the q parameter, and eventually creates an eviladmin account to take over the site.

Unlock to view this content.