BookingPress for WordPress versions before 1.0.11 improperly sanitizes user-supplied POST data used to dynamically construct an SQL query in the bookingpress_front_get_category_services AJAX action. Because this action is available to unauthenticated users, an attacker can trigger SQL injection without authentication.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit auxiliary module targeting a SQL injection vulnerability (CVE-2022-0739) in the BookingPress WordPress plugin (versions prior to 1.0.11). The exploit leverages improper sanitization of the 'total_service' parameter in the 'bookingpress_front_get_category_services' AJAX action, which is accessible to unauthenticated users. The module sends crafted POST requests to the '/wp-admin/admin-ajax.php' endpoint, exploiting the SQL injection to extract sensitive data from the 'wp_users' table, including usernames, email addresses, and password hashes. The extracted credentials are presented in a table and also registered with the Metasploit credential system for further use. The module is written in Ruby and is designed to be used within the Metasploit framework. The only file in the repository is the exploit module itself, and it is fully operational for credential extraction from vulnerable WordPress installations.
This repository contains a proof-of-concept exploit for CVE-2022-0739, targeting a SQL injection vulnerability in the BookingPress WordPress plugin (versions before 1.0.11). The repository consists of a README.md file with usage instructions and a Bash script (exploit.sh) that automates the exploitation process. The script takes a target URL as input, retrieves a required nonce value from the target page, and then performs SQL injection attacks against the /wp-admin/admin-ajax.php endpoint to enumerate database schema names and extract user credentials (usernames and password hashes) from the wp_users table. The exploit demonstrates the vulnerability and the potential for sensitive data exposure but does not provide weaponized or post-exploitation capabilities. The code is straightforward and intended for proof-of-concept and testing purposes.
This repository contains a Bash exploit script (exploit.sh) and a README.md for CVE-2022-0739, an unauthenticated SQL injection vulnerability in BookingPress WordPress plugin versions prior to 1.0.11. The exploit.sh script is the main entry point and is designed to be run from the command line, requiring the target WordPress site URL and optionally an event directory. The script first retrieves a WordPress nonce from the target site, then performs a SQL injection via a POST request to /wp-admin/admin-ajax.php, abusing the 'bookingpress_front_get_category_services' action. The injected SQL extracts user_login, user_email, and user_pass fields from the wp_users table. If successful, the script parses and displays the credentials in a formatted table. The exploit is operational and provides real credential extraction, but is not weaponized for mass exploitation. No hardcoded endpoints or IPs are present; the script is parameterized for the target URL. The repository is well-structured for its purpose, with clear usage instructions and a single exploit script.
This repository contains a proof-of-concept exploit for CVE-2022-0739, targeting a SQL injection vulnerability in the BookingPress WordPress plugin before version 1.0.11. The exploit is implemented in Python (booking-press-expl.py) and requires the attacker to provide the URL of a vulnerable WordPress server and a valid nonce value. The script sends crafted POST requests to the /wp-admin/admin-ajax.php endpoint, exploiting the 'bookingpress_front_get_category_services' action via the 'total_service' parameter. It first checks for vulnerability by fingerprinting the database version, then iterates through the wp_users table to extract usernames, emails, and password hashes. The repository also includes a README.md with a brief description and disclaimer. No hardcoded IPs or domains are present; the target endpoint is specified by the user at runtime.
This repository contains a Python exploit script (booking-sqlinjector.py) targeting CVE-2022-0739, a SQL injection vulnerability in the BookingPress WordPress plugin (version 1.0.10). The exploit automates the process of exploiting the vulnerable AJAX action 'bookingpress_front_get_category_services' by injecting SQL payloads into the 'total_service' parameter of POST requests to /wp-admin/admin-ajax.php. The script can extract the database version, enumerate users (usernames, emails, password hashes), and optionally dump the entire database schema and contents. It supports both direct nonce input and automatic extraction from a supplied URL. The repository includes a README with usage instructions and an example targeting a HackTheBox machine. Only one code file is present, written in Python, and the exploit is operational, providing real data extraction capabilities from vulnerable targets.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.