CVE-2022-21661 is a SQL injection vulnerability in WordPress due to improper sanitization in the WP_Query class. This flaw allows attackers to inject arbitrary SQL queries via plugins or themes that improperly use WP_Query, potentially leading to unauthorized data access or manipulation. The vulnerability affects WordPress core versions prior to 5.8.3, with security releases backported to 3.7.37.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (5 hidden).
This repository is a demonstration environment for exploiting CVE-2022-21661, a SQL injection vulnerability in WordPress Core 5.8.2 and below. The exploit is enabled by a custom 'evil' plugin (src/wp-content/plugins/evil/evil.php) that introduces a vulnerable code path, allowing unsanitized user input to be used in SQL queries. The environment is set up using Docker Compose, with a WordPress 5.8.2 instance and a MariaDB backend. The main attack vector is a POST request to /wp-admin/admin-ajax.php with crafted parameters that trigger a time-based blind SQL injection, as shown in newexploit_req.txt. The exploit allows an unauthenticated attacker to extract sensitive data from the database, such as password hashes, by observing time delays in responses. The repository includes setup instructions, sample requests, and all necessary files to reproduce the vulnerability in a controlled environment. The exploit is operational and demonstrates real-world impact, but requires the installation of the provided malicious plugin to be exploitable.
This repository provides a proof-of-concept (POC) exploit for CVE-2022-21661, a SQL injection vulnerability in WordPress Core versions prior to 5.8.3. The main exploit file (Exploit/50663.txt) details the vulnerability, affected versions, and provides a sample HTTP POST request that targets the /wp-admin/admin-ajax.php endpoint with a malicious 'query_vars' parameter. The exploit is unauthenticated and allows remote attackers to extract sensitive information from the database. The repository also includes a README.md summarizing the exploit and a reference to a demonstration video, but no executable code or automation scripts are present. The structure is simple, with the main technical content in the exploit text file and supporting documentation in the README.
This repository contains a Python exploit script (CVE-2022-21661.py) targeting a time-based blind SQL injection vulnerability (CVE-2022-21661) in the Elementor Custom Skin plugin for WordPress. The script provides three main methods: 'getinfo' (to detect WordPress and plugin versions), 'getuser' (to extract user_login and user_pass from the wp_users table using time-based inference), and 'dnslog' (to trigger DNS exfiltration via a custom SQL payload). The exploit works by sending crafted POST requests to the /wp-admin/admin-ajax.php?action=ecsload endpoint, leveraging the plugin's handling of tax_query parameters. The script is operational and can extract sensitive information from vulnerable WordPress installations. The repository also includes a brief README.md describing the exploit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.