An SQL injection vulnerability exists in the Google Doc Embedder plugin for WordPress prior to version 2.5.15. The vulnerability is present in view.php, where the 'gpid' parameter is not properly sanitized, allowing remote attackers to inject arbitrary SQL commands.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
Repository is a minimal two-file documentation-style exploit package centered on PoC.md, with README.md only repeating the title and attribution. There is no standalone executable exploit file; instead, PoC.md contains a complete exploitation guide for CVE-2014-9173 affecting the WordPress Google Document Embedder plugin. The exploit targets the plugin endpoint view.php and abuses the gpid GET parameter for MySQL time-based blind SQL injection. The document is structured as: prerequisites and timing baseline; manual confirmation payloads using SLEEP() and IF(); length and character extraction examples against `wp_users.user_pass`; a bash script (`gde_timebased_extract.sh`) that automates character-by-character extraction by measuring curl response times; and extensive sqlmap usage examples for detection, enumeration, and dumping WordPress credentials. It also includes payload reference tables, troubleshooting guidance, and timing comparisons. Main capability is database exfiltration through timing side channels rather than code execution. The PoC can confirm vulnerability, enumerate schema/data, and recover WordPress usernames and password hashes from MySQL. Because the repository is primarily markdown with embedded bash snippets and operator instructions, it is best classified as a proof-of-concept exploit rather than a weaponized tool.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.