Sceawere
Vulnerability Detail
CVE-2026-89287UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
ASPL Product Quotation SQL Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.6
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- ASPL Product Quotation
- Attack Type
- CWE-89 SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The ASPL Product Quotation WordPress plugin through 1.1.0 does not sanitize and escape a parameter before using it in SQL statements, allowing unauthenticated attackers to perform SQL injection and read arbitrary data from the database.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.6",
"pubDate": "2026-10-11T07:17:28.560Z",
"pubdate": "2026-10-11T07:17:28.560Z",
"executiveSummary": "The ASPL Product Quotation WordPress plugin through version 1.1.0 contains a critical SQL injection vulnerability. The flaw stems from insufficient input sanitization and improper escaping of user-supplied parameters before they are incorporated into SQL queries. This allows unauthenticated remote attackers to execute arbitrary SQL commands against the underlying database.\nThe impact of this vulnerability is severe, as it grants unauthorized actors the ability to read arbitrary data from the WordPress database, which may include sensitive configuration details, user credentials, or customer information. Successful exploitation does not require authentication, making the attack surface publicly accessible. Organizations utilizing this plugin are at high risk of data exfiltration and potential compromise of the WordPress site integrity. There are currently no documented requirements for high-level privileges to initiate this attack, implying that any remote actor with network access to the application can leverage this vulnerability.\nRemediation requires immediate intervention to either update the software or implement compensating controls to prevent malicious query injection.",
"technicalDetails": "The vulnerability resides in the data handling logic of the ASPL Product Quotation plugin, where input parameters received via HTTP requests are passed directly into database queries without adequate sanitization or the use of prepared statements. The primary root cause is the reliance on unsanitized user input within database interaction functions, failing to utilize the WordPress $wpdb->prepare() method or equivalent parameterization techniques.\nWhen a request is made to the vulnerable endpoint, the plugin fails to perform necessary validation or character escaping on the input fields. Consequently, an attacker can supply specially crafted SQL payloads to terminate or manipulate the intended query structure. By appending a UNION-based or error-based SQL injection string, the attacker can force the database to return results that were not intended by the application logic.\nThe attack flow typically involves the following steps: First, the attacker identifies the parameter used by the plugin for database operations. Second, the attacker crafts a malicious payload—such as ' OR 1=1-- or more complex UNION SELECT statements—designed to reveal table contents or extract sensitive columns from the database. Third, the attacker transmits this payload via an HTTP GET or POST request to the server. Finally, the application executes the contaminated SQL statement, returning the unauthorized data within the HTTP response body or revealing database information through application error messages.\nBecause the plugin lacks access control checks for these specific functions, the vulnerability is exploitable by any unauthenticated remote user. This lack of authentication requirements effectively bypasses the standard security perimeter of the WordPress administrative interface. The post-exploitation impact includes unauthorized information disclosure, which could lead to further attacks such as site takeover if hashed passwords or sensitive site keys are exfiltrated. The vulnerability exists in versions 1.1.0 and prior, indicating that the lack of proper data handling is a fundamental architectural flaw within these versions of the codebase."
}