天下漏洞,尽知其名
MEDIUM

CVE-2026-97634 Event Tickets and Registration SQL注入漏洞

影响具有贡献者及以上权限的攻击者可注入SQL查询,窃取数据库敏感信息

AI 研判

WordPress 插件 Event Tickets and Registration 在 5.29.5 及之前所有版本中,其 orderby 参数存在通用 SQL 注入漏洞。由于对用户输入参数转义不足,且现有 SQL 查询缺乏充分预处理,攻击者可将额外 SQL 查询追加到已有查询中。

影响范围

Event Tickets and Registration

受影响版本为 Event Tickets and Registration 插件 5.29.5 及之前的所有版本。

漏洞详情

漏洞类型为 SQL 注入,成因是 orderby 参数未充分转义且 SQL 查询未使用预处理语句。认证攻击者(贡献者级别及以上)可通过提供自己撰写的 post_id 触发漏洞代码路径,因为 can_access_page() 校验仅要求文章作者身份,而非 edit_others_posts 权限。利用后可向现有查询追加 SQL 语句,从而提取数据库中的敏感信息。

利用条件与风险

利用前提是攻击者需具备贡献者及以上权限并拥有自己撰写的文章;实战中可导致数据库敏感信息泄露,CVSS 评分 6.5,属中危。

修复建议

建议升级至官方修复版本;临时缓解措施包括限制贡献者级别用户权限、对 orderby 参数进行严格白名单校验,具体修复版本暂无公开信息。

原始情报

The Event Tickets and Registration plugin for WordPress is vulnerable to generic SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 5.29.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. A Contributor-level user can reach the vulnerable code path by supplying a post_id they authored, as the can_access_page() gate requires only post authorship rather than the edit_others_posts capability for post owners.