CVE-2017-5611
published 2017-01-30CVE-2017-5611: SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands…
PriorityP275critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
9.93%
95.1th percentile
SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected plugin or theme that mishandles a crafted post type name.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | wordpress | < wordpress 4.7.2+dfsg-1 (bookworm) | wordpress 4.7.2+dfsg-1 (bookworm) |
| oracle | data_integrator | — | — |
| oracle | data_integrator | — | — |
| oracle | data_integrator | — | — |
| wordpress | wordpress | <= 4.7.1 | — |
| wordpress | wordpress | >= 0 < 4.7.2+dfsg-1 | 4.7.2+dfsg-1 |
| wordpress | wordpress | >= 0 < 4.7.2+dfsg-1 | 4.7.2+dfsg-1 |
| wordpress | wordpress | >= 0 < 4.7.2+dfsg-1 | 4.7.2+dfsg-1 |
| wordpress | wordpress | >= 0 < 4.7.2+dfsg-1 | 4.7.2+dfsg-1 |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered via a crafted post type name passed through plugins or themes to WP_Query; inspect HTTP requests containing unusual post_type parameter values for SQL metacharacters. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vulncheck9.8CRITICAL
vendor_debian9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
WordPress up to 4.7.1 WP_Query class-wp-query.php sql injection (EDB-41223 / Nessus ID 96906)
vuldb·2026-05-16·CVSS 9.8
CVE-2017-5611 [CRITICAL] WordPress up to 4.7.1 WP_Query class-wp-query.php sql injection (EDB-41223 / Nessus ID 96906)
A vulnerability marked as critical has been reported in WordPress up to 4.7.1. This vulnerability affects unknown code of the file wp-includes/class-wp-query.php of the component WP_Query. The manipulation leads to sql injection.
This vulnerability is referenced as CVE-2017-5611. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
It is suggested to upgrade the affected component.
GHSA
GHSA-r745-4v47-m5c7: SQL injection vulnerability in wp-includes/class-wp-query
ghsa_unreviewed·2022-05-13
CVE-2017-5611 [CRITICAL] CWE-89 GHSA-r745-4v47-m5c7: SQL injection vulnerability in wp-includes/class-wp-query
SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected plugin or theme that mishandles a crafted post type name.
OSV
CVE-2017-5611: SQL injection vulnerability in wp-includes/class-wp-query
osv·2017-01-30·CVSS 9.8
CVE-2017-5611 [CRITICAL] CVE-2017-5611: SQL injection vulnerability in wp-includes/class-wp-query
SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected plugin or theme that mishandles a crafted post type name.
VulnCheck
WordPress wordpress Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
vulncheck·2017·CVSS 9.8
CVE-2017-5611 [CRITICAL] WordPress wordpress Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
WordPress wordpress Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected plugin or theme that mishandles a crafted post type name.
Affected: WordPress wordpress
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.ic3.gov/Media/News/2022/220126.pdf
Debian
CVE-2017-5611: wordpress - SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in Wor...
vendor_debian·2017·CVSS 9.8
CVE-2017-5611 [CRITICAL] CVE-2017-5611: wordpress - SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in Wor...
SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected plugin or theme that mishandles a crafted post type name.
Scope: local
bookworm: resolved (fixed in 4.7.2+dfsg-1)
bullseye: resolved (fixed in 4.7.2+dfsg-1)
forky: resolved (fixed in 4.7.2+dfsg-1)
sid: resolved (fixed in 4.7.2+dfsg-1)
trixie: resolved (fixed in 4.7.2+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-5610 CVE-2017-5611 CVE-2017-5612 wordpress: Multiple security fixes in 4.7.2 [epel-all]
bugzilla·2017-01-27·CVSS 5.3
CVE-2017-5610 [MEDIUM] CVE-2017-5610 CVE-2017-5611 CVE-2017-5612 wordpress: Multiple security fixes in 4.7.2 [epel-all]
CVE-2017-5610 CVE-2017-5611 CVE-2017-5612 wordpress: Multiple security fixes in 4.7.2 [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
Bugzilla
CVE-2017-5610 CVE-2017-5611 CVE-2017-5612 wordpress: Multiple security fixes in 4.7.2 [fedora-all]
bugzilla·2017-01-27·CVSS 5.3
CVE-2017-5610 [MEDIUM] CVE-2017-5610 CVE-2017-5611 CVE-2017-5612 wordpress: Multiple security fixes in 4.7.2 [fedora-all]
CVE-2017-5610 CVE-2017-5611 CVE-2017-5612 wordpress: Multiple security fixes in 4.7.2 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple s
Bugzilla
CVE-2017-5610 CVE-2017-5611 CVE-2017-5612 wordpress: Multiple security fixes in 4.7.2
bugzilla·2017-01-27·CVSS 5.3
CVE-2017-5610 [MEDIUM] CVE-2017-5610 CVE-2017-5611 CVE-2017-5612 wordpress: Multiple security fixes in 4.7.2
CVE-2017-5610 CVE-2017-5611 CVE-2017-5612 wordpress: Multiple security fixes in 4.7.2
WordPress versions 4.7.1 and earlier are affected by three security issues:
1. The user interface for assigning taxonomy terms in Press This is shown to users who do not have permissions to use it.
2. WP_Query is vulnerable to a SQL injection (SQLi) when passing unsafe data. WordPress core is not directly vulnerable to this issue, but we’ve added hardening to prevent plugins and themes from accidentally causing a vulnerability.
3. A cross-site scripting (XSS) vulnerability was discovered in the posts list table.
External Reference:
https://wordpress.org/news/2017/01/wordpress-4-7-2-security-release/
Discussion:
Created wordpress tracking bugs for this issue:
Affects: fedora-all [bug 1417159]
Aff
http://www.debian.org/security/2017/dsa-3779http://www.openwall.com/lists/oss-security/2017/01/28/5http://www.securityfocus.com/bid/95816http://www.securitytracker.com/id/1037731https://codex.wordpress.org/Version_4.7.2https://github.com/WordPress/WordPress/commit/85384297a60900004e27e417eac56d24267054cbhttps://wordpress.org/news/2017/01/wordpress-4-7-2-security-release/https://wpvulndb.com/vulnerabilities/8730https://www.oracle.com/security-alerts/cpujan2021.htmlhttp://www.debian.org/security/2017/dsa-3779http://www.openwall.com/lists/oss-security/2017/01/28/5http://www.securityfocus.com/bid/95816http://www.securitytracker.com/id/1037731https://codex.wordpress.org/Version_4.7.2https://github.com/WordPress/WordPress/commit/85384297a60900004e27e417eac56d24267054cbhttps://wordpress.org/news/2017/01/wordpress-4-7-2-security-release/https://wpvulndb.com/vulnerabilities/8730https://www.oracle.com/security-alerts/cpujan2021.html
2017-01-30
Published
Exploited in the wild