Sceawere
Vulnerability Detail
CVE-2026-39747UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Woffice Subscriber SQL Injection Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.5
- Creation Date
- 16h ago
- Vendor
- WofficeIO
- Product
- Woffice
- Attack Type
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Subscriber SQL Injection in Woffice <= 5.4.35 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.5",
"pubDate": "2026-10-06T09:17:46.033Z",
"pubdate": "2026-10-06T09:17:46.033Z",
"executiveSummary": "Woffice versions 5.4.35 and earlier contain a SQL Injection vulnerability that allows authenticated users with Subscriber-level privileges to execute arbitrary SQL queries against the underlying database.\nThe vulnerability arises from insufficient sanitization of user-supplied input before it is incorporated into database queries.\nAn attacker can exploit this flaw to bypass security controls, perform unauthorized data exfiltration, modify database content, or escalate privileges within the application.\nThe attack is performed via the application's interface, requiring the attacker to have an active Subscriber account.\nSuccessful exploitation results in full database access, potentially leading to complete compromise of the WordPress installation and its data.\nThis vulnerability poses a significant security risk, as it allows low-privileged users to circumvent intended access restrictions and interact directly with the database layer.",
"technicalDetails": "The Woffice plugin is susceptible to SQL Injection (SQLi) because it fails to properly validate and escape input parameters processed by its backend functions. This vulnerability exists in Woffice versions 5.4.35 and below.\nThe root cause of this vulnerability is the concatenation of unsanitized user-supplied input directly into SQL queries executed by the application. Instead of utilizing prepared statements or parameterized queries provided by the WordPress wpdb class, the application improperly constructs dynamic queries. This allows an attacker to inject arbitrary SQL commands into the parameter fields processed by affected functions.\nThe attack flow requires an attacker to be authenticated as a user with at least Subscriber-level privileges. Once authenticated, the attacker can submit crafted input via affected request parameters. When these inputs reach the vulnerable server-side components, they manipulate the structure of the intended SQL query.\nBy leveraging SQL injection techniques, such as UNION-based, error-based, or boolean-based blind injection, an attacker can extract sensitive information stored in the WordPress database, including user credentials, configuration data, and application-specific content.\nFurthermore, depending on the database configuration and the privileges of the database user account used by the WordPress application, an attacker may be able to modify, delete, or add new entries to the database. In some scenarios, this level of access can be leveraged to escalate privileges, for example, by modifying the 'wp_users' table to promote a low-privileged account to an Administrator.\nThe vulnerability is reachable over the network and requires the attacker to interact with specific plugin-related endpoints that do not adequately secure input parameters. The lack of proper input validation and the failure to employ secure database query practices represent the primary technical deficiencies.\nPost-exploitation impact includes unauthorized data access, the potential for complete site takeover via administrative privilege escalation, and the ability to manipulate the application's functionality. This makes the vulnerability highly critical, especially in environments where Subscriber accounts are publicly registerable."
}