Web Hack List

Top 10 winner

Prepare(): Introducing Novel Exploitation Techniques in WordPress

Prepare(): Introducing novel Exploitation Techniques in WordPress

WordPress before 4.8.3 allowed SQL injection when prepare() was applied twice to input containing placeholders. Its fix introduced secret percent-sign tokens: when a WP_Query containing those tokens is serialized for transient caching, query() restores percent signs after serialization and shortens the stored string without updating its length prefix. Controlled later data can then inject a PHP object, illustrated through an authenticated WooCommerce RCE path.

Record

Document
Prepare(): Introducing novel Exploitation Techniques in WordPress
Researcher
Robin Peraglie
Published by
OWASP AppSec Europe
Format
Slides
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Robin Peraglie, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .