• Home
  • About Us
  • Authors
  • Submit News
  • Contact Us
  • Privacy Policy
  • Sitemap
The Hack Post
  • Hacking News
    • Cyber Crime
  • Cyber Security
  • Technology
    • Internet
  • Entertainment
    • Gaming
  • Business
  • Science / Health
No Result
View All Result
The Hack Post
No Result
View All Result

WordPress < 4.8.3 Vulnerable To SQL Injection (SQLI) Exploit

Connor Stewart by Connor Stewart
November 1, 2017
WordPress SQL Injection
Share on FacebookShare on Twitter

A security researcher named “Anthony Ferrara” has found a critical SQL Injection (SQLI) vulnerability in the WordPress CMS. According to WordPress team, the vulnerability exists in all previous versions of the CMS, Whereas the vulnerability has been patched in the latest WordPress version 4.8.3 released which was released yesterday. Therefore, WordPress has strongly encouraged all it’s CMS users to upgrade their scripts to the latest version as soon as possible.

WordPress reported that the issue comes from $wpdb->prepare(), which can create unexpected and unsafe queries leading to an SQL Injection (SQLI). WordPress team have said that the vulnerability is not in the core script, but can be caused by plugins and themes using $wpdb->prepare(). WordPress had been made changes to the esc_sql() function to prevent SQL Injection queries, However the changes wont have any effects on WordPress developers.

The vulnerability founder, Anthony Ferrara shared a story on his blog on how he got WordPress team to pay attention to the bug reported. Although WordPress had literally ignored the bug, thinking it wasn’t a vulnerability. After Anthony Ferrara asked permission for disclosing the vulnerability to the public, WordPress team decided to have another look into the reported vulnerability, which then was found to be a serious flaw.

The vulnerability was originally found on 19th September 2017, which then was reported to WordPress on 20th September 2017. On 27 October 2017, Anthony Ferrara shared a tweet on Facebook regarding him disclosing the SQL Injection vulnerability in WordPress soon.

IMPORTANT: I will be disclosing a massive WP SQLi vulnerability soon. I have no confidence WP will fix correctly and hence no choice but FD

— Anthony Ferrara (@ircmaxell) October 26, 2017

That being said, On 31st October 2017, Anthony Ferrara published an article on his blog on how the vulnerability works, what code causes the CMS to break and how to fix the buggy code in steps. WordPress also thanked Anthony Ferrara for reporting the vulnerability and for practicing responsible disclosure.

Back in February, WordPress was vulnerable to a REST API exploit which had lead to thousands of websites being hacked and defaced. As the new SQL Injection vulnerability has just been disclosed to the public, we hope it won’t result in the same outcome as it did with the REST API vulnerability.

Tags: SQL InjectionWordpress
Connor Stewart

Connor Stewart

Connor is an Editor at The Hack Post.

Next Post
Hacked By Team Bad Dream

Ministry of Foreign Affairs and 20 Embassy Websites of Lebanon Hacked

Latest Articles

Modern city skyline with new developments symbolizing upcoming real estate market trends
Business

Future-Proof Your Investments – Understanding 2026 Real Estate Market Trends

November 11, 2025
Modern suburban houses with for-sale signs representing real estate opportunities for first-time buyers
Business

Exploring 2026 Real Estate Trends – Opportunities for First-Time Buyers

November 11, 2025
Modern eco-friendly luxury home featuring green roofs and sustainable architectural elements
Business

Sustainable Luxury — How Eco-Conscious Design Shapes Modern Residences

November 10, 2025
Image 1 of Metrotest Expands Access to Electrical Safety Training With Free Introductory Programme
Business

Metrotest Expands Access to Electrical Safety Training With Free Introductory Programme

November 6, 2025
Industrial crushing and rolling machinery processing raw materials for manufacturing operations
Business

A Guide to Crushing and Rolling Technologies

November 2, 2025
Artificial intelligence technology enhancing mental health care solutions and support systems
Business

Stanley Vashovsky: A practical look at AI’s role in mental health care

October 30, 2025
Small dog relaxing on a balcony with city buildings in the background, adapting to condo living
Featured

How to Help Your Dog Adapt to Condo Life

October 29, 2025
CBD products and digital shopping cart illustrating online CBD purchasing in the UK
Cyber Security

Buying CBD Online in the UK: A Cyber-Savvy Buyer’s Guide

October 29, 2025
Person walking on a tree-lined path, promoting daily walking tips for a healthy lifestyle
Business

5 Tips for Consistent Daily Walks

September 27, 2025
Modern luxury condo interior with stylish furnishings, showcasing enhanced resale value features
Business

5 Tips to Boost the Resale Value of Your Luxury Condo

September 16, 2025
Modern home office with standing desk, ergonomic chair, laptop, and indoor plants for productivity
Business

4 Surprising Benefits of Standing While Working at Home

September 13, 2025
Colorful online slot machine reels and winning symbols highlighting strategies for extended win streaks
Gaming

How to Make a Beginner Win Streak Last: Smart Tips for Online Slot Games

September 13, 2025
  • Home
  • About Us
  • Authors
  • Submit News
  • Contact Us
  • Privacy Policy
  • Sitemap

The Hack Post © 2019

No Result
View All Result
  • Hacking News
    • Cyber Crime
  • Cyber Security
  • Technology
    • Internet
  • Entertainment
    • Gaming
  • Business
  • Science / Health

The Hack Post © 2019