=========================================
[+] Title : wordpress-newsletter * wordpress plugin * SQL Injection
[+] Author : Abolfazl Feyz
[+] Vendor : https://github.com/wp-plugins/wordpress-newsletter/archive/master.zip
[+] Dork : inurl:plugins/wordpress-newsletter-master
[+] date : 16.January.2021
===========================================
Vulnerable page:
/wp-content/plugins/wordpress-newsletter-master/newsletter.php
------------------------------------
---------------------------------------------------
Vulnerable source:
Line241: $wpnewsletter_ip = $_GET['kei'];
Line243: $wpnewsletter_ip = checkvalid($wpnewsletter_ip);
Line247: $sql = "SELECT * FROM `" . $dbprefix . "newsletter_users` WHERE MD5(CONCAT(`email`, `name`)) = '" . $wpnewsletter_ip . "'";
Line249: mysql_query $result = mysql_query($sql);
==============================================
===========================================
POC :
http://site.com/wp-content/plugins/wordpress-newsletter-master/newsletter.php?wpnewsletter_ip=[SQL Injection]
==============================================
***************************************
* cantact me *
* Telegram ==> Mr_ramkal *
* instagram ==> aboolfazl_feyz *
* email ==> khodebolfazl@gmail.com *
**************************************