Detects 'SQL Injection' vulnerability in Steveas WP Live Chat Shoutbox affects v. <= 1.4.2


Steveas WP Live Chat Shoutbox is a WordPress plugin that provides live chat functionality, allowing website owners to offer real-time support and interaction capabilities to their site visitors. It is designed to enhance user engagement and provide immediate communication channels on WordPress-based websites. This plugin is commonly used in customer service and support applications on eCommerce sites, blogs, and online communities. The plugin’s popularity stems from its ease of use and integration into WordPress sites, making it a preferred choice for webmasters looking to improve their customer service capabilities.

The SQL Injection vulnerability in Steveas WP Live Chat Shoutbox plugin version 1.4.2 and below stems from the plugin's failure to properly sanitise and escape user-supplied data before using it in SQL queries. This security flaw allows unauthenticated attackers to execute arbitrary SQL commands through the plugin's AJAX action handler. Such vulnerabilities are critical as they can lead to unauthorized access to the website's database, data theft, and potentially complete site compromise.

Specifically, the vulnerability exists in an AJAX action available to unauthenticated users, where parameters such as 'last_timestamp' are not correctly sanitized. By manipulating SQL queries through the AJAX endpoint, attackers can inject malicious SQL code into the website’s database. This could lead to unauthorized reading, updating, or deleting data in the database, affecting the integrity and confidentiality of the site’s data. The exploitation of this vulnerability can lead to serious security breaches, including access to sensitive information.

Exploitation of this SQL Injection vulnerability could lead to a range of adverse effects, including unauthorized access to sensitive data within the website's database, modification or deletion of data, database corruption, and potentially taking full control of the affected website. This could result in significant reputational damage, financial loss, and legal implications for the website owner. Furthermore, attackers could leverage the compromised site to distribute malware or conduct phishing attacks.

