Unauthenticated SQL Injection in the WordPress plugin asAffili (1.1.1)
asAffili (WordPress.org, version 1.1.1) The WordPress plugin asAffili (1.1.1) registers a public, unauthenticated admin-ajax.php action whose handler builds a SQL query by string concatenation. A request parameter is passed only through sanitize_text_field() — which strips tags but does not escape SQL — so an unauthenticated visitor can inject SQL and read arbitrary database contents (WordPress user password hashes, secrets). A second authenticated (Subscriber+) variant with no nonce or capability check exists in the same file, along with several further unparameterised queries. The plugin has been unmaintained since January 2020; no fixed release exists — remove it.
asAffili 1.1.1 (WordPress.org) contains an unauthenticated sql injection. The plugin registers a handler reachable by visitors who are not logged in, and it concatenates a request parameter straight into a live SQL statement.
The only input handling is sanitize_text_field(), which strips HTML tags but performs no SQL escaping, so the value reaches the database driver unparameterised. The result is a blind/time-based SQL-injection channel through which the full database (user password hashes, secrets) can be extracted.
asAffili was surfaced automatically by the codelake WordPress static-analysis pipeline (source-to-sink taint) · AI false-positive triage · manual source verification, and then verified by hand against the shipped 1.1.1 artifact. The plugin has not been updated since 2020-01-05; because no patched release exists, the correct remediation is to remove it.
Class: SQL Injection (CWE-89). Privilege required: none — the injectable endpoint is registered for logged-out visitors. Effect: read access to the entire database via blind SQL injection (credential hashes, secrets, tokens); depending on database privileges, write access.
A second variant with the same flaw exists in the same file. The precise locations and code are withheld below until the disclosure deadline.
8:00 UTC
Detected by codelake Research · codelake WordPress static-analysis pipeline (source-to-sink taint) · AI false-positive triage · manual source verification · disclosed to WordPress Plugin Security Team before publication.
This is a coordinated vulnerability disclosure. The affected package, version and class are published immediately so defenders can act; the exact code location and reproduction are withheld until the deadline, and no weaponised proof-of-concept is published. The archived artifact is available to verified security researchers on request.