
🚨 CVE-2024-3495 : CRITICAL WORDPRESS SQL INJECTION ALERT 🚨 An unauthenticated SQL injection vulnerability has been disclosed in the Country State City Dropdown CF7 WordPress plugin, exploitable via exposed AJAX endpoints and requiring no authentication or user interaction. Risk Severity: - Critical (CVSS 9.8, active exploitation, public exploits available, trending) Impact: - Unauthenticated SQL injection - Complete WordPress database compromise - Administrator credential theft - Authentication bypass & site takeover - Potential remote code execution via webshell deployment - Ransomware and data destruction scenarios Root Cause: - CWE-89 (Improper Neutralization of Special Elements in SQL Commands). The plugin directly concatenates user-supplied `cnt` (country) and `sid` (state) parameters into SQL queries within its AJAX handlers without using prepared statements or proper input sanitization. Attackers can: - Send crafted requests to `admin-ajax.php` endpoints without authentication - Inject arbitrary SQL via location dropdown parameters - Exfiltrate sensitive data including `wp_users` credentials and site secrets - Modify database content or plant persistent backdoors Are You Affected? - Vulnerable: Country State City Dropdown CF7 versions ≤ 2.7.2 - Scope: Internet-facing WordPress sites using Contact Form 7 with this plugin enabled Immediate Action Required: - Update: Upgrade to version 2.7.3 or later immediately - Mitigation: Disable and remove the plugin if patching cannot be completed at once - Audit: Monitor `admin-ajax.php` for suspicious `cscf7_get_*` requests and review database logs for injection artifacts This vulnerability is being actively scanned and exploited at scale. Unpatched WordPress sites should be assumed exposed. 🛡️ #ostorlabCVE
Post summary
CVE-2024-3495 is a critical unauthenticated WordPress SQL injection affecting the Country State City Dropdown CF7 plugin. The vulnerability is actively exploited in the wild, public exploits exist, and a patch (v2.7.3) is available.
