CVE-2024-1071 is a critical SQL injection vulnerability in the Ultimate Member plugin for WordPress. Affected versions are 2.1.3 through 2.8.2. The flaw is caused by insufficient escaping of the user-controlled 'sorting' parameter together with inadequate preparation of the resulting SQL query, allowing attacker-supplied SQL fragments to be appended to an existing query. The issue is present in deployments where the plugin option to use a custom table for user metadata is enabled. The vulnerability can be exploited without authentication and supports database interrogation, including blind or time-based extraction techniques, to retrieve sensitive information from the WordPress database.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit auxiliary scanner module targeting CVE-2024-1071, a SQL injection vulnerability in the Ultimate Member plugin for WordPress (versions up to 2.8.2). The exploit is implemented in Ruby and leverages Metasploit's framework for HTTP and WordPress-specific exploitation. The module works by first brute-forcing registration page IDs to retrieve a valid nonce, then brute-forcing directory IDs, and finally performing a time-based blind SQL injection via the 'sorting' parameter in POST requests to /wp-admin/admin-ajax.php. If successful, it extracts user credentials from the WordPress database. The code is operational and provides automated exploitation and data extraction, but does not include a customizable payload beyond the SQLi logic. The only file present is the Metasploit module itself, and all logic is contained within this file.
This repository provides a Python proof-of-concept exploit for CVE-2024-1071, a SQL injection vulnerability in the Ultimate Member WordPress plugin (versions 2.1.3 to 2.8.2). The exploit automates the process of checking if a target WordPress site is running a vulnerable version of the plugin, retrieves a required nonce from the registration page, brute-forces a valid directory_id, and constructs the necessary POST data to exploit the SQL injection vulnerability in the 'sorting' parameter of the /wp-admin/admin-ajax.php endpoint. The script is designed to be run against a list of targets provided in a file. If a target is found vulnerable, it outputs the exact sqlmap command to exploit the SQL injection. The repository consists of the main exploit script (CVE-2024-1071.py) and a README with usage instructions, references, and legal disclaimers. No hardcoded payload is included; the script facilitates exploitation by providing the necessary parameters for tools like sqlmap.
This repository contains a Python proof-of-concept exploit for CVE-2024-1071, a SQL injection vulnerability in the WordPress Ultimate Member plugin (versions 2.1.3 to 2.8.2). The exploit is implemented in 'spiXploite.py', which automates the process of checking if a target is vulnerable, retrieving necessary parameters (nonce and directory ID), and then launching SQLMap to exploit the SQL injection via the 'sorting' parameter in POST requests to '/wp-admin/admin-ajax.php'. The script can scan a single target or multiple targets from a file. The README provides background, usage instructions, and dorks for finding potential targets. The exploit is unauthenticated and targets network-accessible WordPress sites with the vulnerable plugin. No hardcoded credentials or static payloads are present; the script dynamically interacts with the target and leverages SQLMap for exploitation. The repository is structured simply, with a single Python exploit script and a README.
This repository contains a proof-of-concept exploit (exploit.py) for CVE-2024-1071, targeting the Ultimate Member WordPress plugin (versions >2.1.2 and <2.8.3). The exploit script is written in Python and automates the process of: - Checking if the target site is running a vulnerable version of the plugin by fetching and parsing the plugin's readme.txt file. - Retrieving a required nonce value from the registration page. - Brute-forcing a valid directory_id parameter by sending POST requests to the admin-ajax.php endpoint. Once these parameters are obtained, the script outputs a ready-to-use sqlmap command, allowing the user to exploit the SQL injection vulnerability in the 'sorting' parameter of the um_get_members AJAX action. The repository structure is simple, consisting of a README.md (with a brief description and screenshot) and the main exploit script (exploit.py). The exploit does not itself perform the SQL injection but prepares all necessary data for use with sqlmap, making it a practical and effective POC for unauthorized database access via SQLi.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A SQL injection vulnerability in the WordPress Ultimate Member plugin, referenced as a Metasploit module PR.
A critical unauthenticated SQL injection vulnerability in the WordPress Ultimate Member plugin that can allow unauthorized access to sensitive information.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.