PT-2026-54629 · WordPress · Houzez Property Feed
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Houzez Property Feed versions prior to 2.5.47
Description
The plugin is susceptible to SQL Injection, a technique where malicious SQL statements are inserted into entry fields for execution. The issue occurs in the
prepare items() method of the Houzez Property Feed Admin Logs Export Table and Houzez Property Feed Admin Logs Import Table classes. Authenticated attackers with Administrator-level access or higher can exploit this by manipulating the orderby and order parameters via $ GET requests. Because these values are only processed with sanitize text field() and concatenated into the SQL string before the $wpdb->prepare() function is called, the ORDER BY clause remains insecure. This allows the attacker to append additional SQL queries to extract sensitive information from the database.Recommendations
Update to a version later than 2.5.46.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Houzez Property Feed