Sceawere
Vulnerability Detail
CVE-2026-96331UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Ajax Search Pro SQL Injection
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.3
- Creation Date
- 3h ago
- Vendor
- wpdreams
- Product
- Ajax Search Pro
- Attack Type
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdreams Ajax Search Pro ajax-search-pro allows Blind SQL Injection.This issue affects Ajax Search Pro: from n/a through 4.29.1.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.3",
"pubDate": "2026-10-09T10:16:44.167Z",
"pubdate": "2026-10-09T10:16:44.167Z",
"executiveSummary": "The Ajax Search Pro plugin for WordPress is susceptible to a Blind SQL Injection vulnerability, identified under the category of Improper Neutralization of Special Elements used in an SQL Command (CWE-89).\nThis vulnerability impacts all versions of the Ajax Search Pro plugin from n/a through 4.29.1.\nThe flaw resides within the handling of user-supplied data, allowing an unauthenticated remote attacker to execute arbitrary SQL queries against the underlying database.\nSuccessful exploitation permits unauthorized access to sensitive information, potential data exfiltration, and manipulation of database content.\nThe risk implication is critical, as it bypasses standard application-layer security controls. Attackers do not require prior authentication to leverage this flaw, as the vulnerability is reachable through the plugin's search functionalities.\nExposure of this nature can lead to full compromise of the database integrity and confidentiality. Mitigation necessitates urgent intervention, typically involving the application of vendor-provided security patches or disabling the vulnerable component until updates are verified.",
"technicalDetails": "The vulnerability manifests due to the failure of the Ajax Search Pro plugin to adequately sanitize or parameterize user-supplied input before incorporating it into dynamic SQL queries.\nIn versions 4.29.1 and earlier, specific search parameters or filtering criteria processed by the plugin are passed directly into database query strings. Because these inputs are not neutralized, an attacker can inject malicious SQL fragments to manipulate the structure of the intended query.\nThe vulnerability is specifically a Blind SQL Injection, which indicates that the application does not necessarily output the results of the query directly to the user interface. Instead, the attacker can infer database content or structure by observing how the application's response changes based on true or false conditions injected into the query (Boolean-based), or by measuring time-based delays triggered by heavy database functions (Time-based).\nThe attack flow initiates when an unauthenticated actor submits a crafted HTTP request to the vulnerable endpoint associated with the Ajax Search Pro search functionality. By appending SQL syntax—such as 'AND (SELECT 1 FROM (SELECT(SLEEP(5)))a)--'—an attacker can force the database to pause, confirming the vulnerability existence.\nOnce confirmed, the attacker can systematically extract data from the database. This process involves executing subqueries to iterate through table names, column names, and row values. Since the search plugin interfaces with the WordPress database, the attacker may target sensitive tables such as 'wp_users' to extract password hashes, session tokens, or administrative credentials.\nThe vulnerable component is the query generation engine within the plugin. Because the input is processed without adequate validation or the use of prepared statements (parameterized queries), the database engine executes the injected logic alongside the legitimate search request.\nThere are no authentication or elevated privilege requirements for this exploit, as the target endpoints are generally exposed to the public-facing side of the WordPress installation to facilitate search functionality for visitors.\nPost-exploitation impact includes unauthorized data exfiltration, potential privilege escalation if administrative credentials are recovered, and in some database configurations, the ability to write to or modify tables, potentially leading to full site compromise or further injection of malicious scripts into the application environment."
}