Top 10 winner
Prepare(): Introducing Novel Exploitation Techniques in WordPress
Prepare(): Introducing novel Exploitation Techniques in WordPress
WordPress before 4.8.3 allowed SQL injection when prepare() was applied twice to input containing placeholders. Its fix introduced secret percent-sign tokens: when a WP_Query containing those tokens is serialized for transient caching, query() restores percent signs after serialization and shortens the stored string without updating its length prefix. Controlled later data can then inject a PHP object, illustrated through an authenticated WooCommerce RCE path.
Record
- Document
- Prepare(): Introducing novel Exploitation Techniques in WordPress
- Researcher
- Robin Peraglie
- Published by
- OWASP AppSec Europe
- Format
- Slides
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Robin Peraglie, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .