CVE-2024-43917 is a critical unauthenticated SQL injection vulnerability in the TI WooCommerce Wishlist WordPress plugin (versions up to and including 2.8.2). The vulnerability arises from improper neutralization of user-supplied input in SQL queries within the get() and get_wishlists_data() functions, allowing attackers to inject arbitrary SQL via both REST API and AJAX endpoints without authentication.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Python proof-of-concept exploit for CVE-2024-43917, a SQL injection vulnerability in the TI WooCommerce Wishlist WordPress plugin (versions <= 2.8.2). The exploit script (CVE-2024-43917.py) takes as input a SQL command and a wishlist share key, and targets the vulnerable REST API endpoint '/wp-json/wc/v3/wishlist/{SHARE_KEY}/get_products' on a specified host and port (with optional HTTPS). It first checks if the target is vulnerable by sending a benign SQL injection, then attempts to execute the supplied SQL command via the 'order' parameter. The README.md provides usage instructions, affected versions, and patch guidance. The exploit requires knowledge of a valid wishlist share key and network access to the target's REST API. No hardcoded endpoints or credentials are present; the script is a generic PoC for the described vulnerability.
This repository contains a single Metasploit auxiliary scanner module targeting an unauthenticated SQL injection vulnerability (CVE-2024-43917) in the TI WooCommerce Wishlist WordPress plugin (versions <= 2.8.2). The module is written in Ruby and leverages Metasploit's HTTP and SQLi mixins. Its main capabilities are: - Brute-forcing product IDs to retrieve a valid 'share key' required for exploitation. - Performing a time-based blind SQL injection via crafted HTTP POST and GET requests to the plugin's REST API endpoint. - Extracting sensitive information from the WordPress database, such as user credentials, if the target is vulnerable. The module is operational and automates the exploitation process, requiring only the target URL and a product ID range. It is not a detection script but a full exploit. The endpoints involved are typical of WordPress plugin AJAX and REST API routes. The code is structured as a standard Metasploit module, with clear separation of initialization, exploitation logic, and result handling.
This repository contains a Python exploit script (CVE-2024-43917.py) and a README.md. The exploit targets an unauthenticated SQL injection vulnerability (CVE-2024-43917) in the TI WooCommerce Wishlist WordPress plugin (versions up to 2.8.2). The script first checks for the vulnerability by sending a crafted GET request to the plugin's REST API endpoint, attempting to inject SQL via the 'order' parameter. If the check is positive, it proceeds to exploit the vulnerability by injecting a UNION SELECT statement to extract usernames and password hashes from the WordPress 'wp_users' table. The main endpoint targeted is the plugin's REST API at '/wp-json/wishlist/v1/{share_key}/get_products'. The exploit is operational, providing a working payload and demonstrating the ability to extract sensitive data from a vulnerable target. The repository is structured simply, with the main exploit logic in a single Python file and usage instructions in the README.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.