CVE-2026-6806 WordPress Motors 插件盲注 SQL 注入漏洞
影响未授权攻击者可注入 SQL 并窃取数据库敏感信息
WordPress 的 Motors – Car Dealership & Classified Listings 插件存在基于时间的盲注 SQL 注入漏洞。由于对用户传入的 stm_lat/stm_lng 参数转义不足且 SQL 查询未做充分预处理,攻击者可将额外 SQL 语句拼接到原有查询中。该漏洞影响 1.4.109 及之前的所有版本。
影响范围
Motors – Car Dealership & Classified Listings Plugin 1.4.109 及之前的所有版本。
漏洞详情
漏洞类型为基于时间的盲注 SQL 注入。成因是插件在处理 stm_lat/stm_lng 参数时未进行充分转义,且未对 SQL 查询使用预处理语句。未授权攻击者可通过构造恶意参数值,将额外 SQL 查询追加到现有查询中,并借助时间延迟判断注入结果,从而逐步提取数据库中的敏感信息。
利用条件与风险
利用无需身份认证,攻击者只需能访问相关接口即可发起注入;实战中可导致数据库敏感数据泄露,风险较高。
修复建议
建议升级到官方修复版本;若暂无可用补丁,可对 stm_lat/stm_lng 参数进行严格过滤与转义,或通过 WAF 拦截相关注入请求作为临时缓解。
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the ‘stm_lat/stm_lng’ parameter in all versions up to, and including, 1.4.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.