CVE-2024-1698 is a SQL Injection vulnerability in the NotificationX WordPress plugin (all versions up to and including 2.8.2). The vulnerability exists due to insufficient escaping and lack of proper preparation of the 'type' parameter in SQL queries, allowing unauthenticated attackers to inject arbitrary SQL code via this parameter. This can be exploited to extract sensitive information from the WordPress database.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone proof-of-concept exploit for CVE-2024-1698 affecting the WordPress NotificationX plugin. It contains two files: a README describing the vulnerability and usage context, and a single Python script, exploit.py, which is the operational exploit entry point. The script uses the requests library and a persistent HTTP session to send repeated POST requests to the NotificationX REST endpoint /wp-json/notificationx/v1/analytics. The attack is an unauthenticated time-based blind SQL injection delivered through the POST parameter type, while nx_id is set to 1337. The exploit first determines the length of the administrator username using IF(LENGTH(...)=N,SLEEP(delay),null), then brute-forces each character with ASCII(SUBSTRING(...)) comparisons. It repeats the same technique against the user_pass field to recover the administrator password hash. The code assumes the admin account is id=1 and that the WordPress table prefix is the default wp_. The target URL is hardcoded to http://192.168.100.10/wordpress/wp-json/notificationx/v1/analytics, indicating the script is intended to be edited for a real target rather than used as-is. There is no shell payload or post-exploitation logic; the exploit’s purpose is credential extraction via SQLi, after which the recovered phpass hash could be cracked offline.
This repository contains a proof-of-concept Python exploit script (exploit.py) and a README.md. The exploit targets CVE-2024-1698, a time-based blind SQL injection vulnerability in the NotificationX WordPress plugin (versions <= 2.8.2). The script automates the extraction of the WordPress admin's username and password hash by sending crafted POST requests to the vulnerable NotificationX Analytics API endpoint (/wp-json/notificationx/v1/analytics). It measures response times to infer correct characters in the credentials, iterating through possible values to reconstruct the admin's username and password hash. The README provides usage instructions, legal disclaimers, and background on the vulnerability. The exploit is a standalone Python script requiring the 'requests' library and is intended for educational and authorized penetration testing purposes only.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.