CyberRota Analysis
AI-GeneratedThe Object Sync for Salesforce plugin in WordPress is vulnerable to unauthenticated SQL Injection due to improper handling of the `wordpress_object_type` parameter in its REST API endpoint. This flaw allows attackers to execute arbitrary SQL queries, potentially leading to the extraction of sensitive data, including password hashes, without any authentication required. WordPress site administrators using this plugin should prioritize patching or mitigating this vulnerability to protect their databases from unauthorized access.
Original NVD Description
The Object Sync for Salesforce plugin is vulnerable to unauthenticated SQL Injection via the wordpress_object_type parameter of its /wp-json/object-sync-for-salesforce/push/ REST route. The route's permission callback (can_process()) checks only the HTTP method for the push class — no capability or nonce — so it is reachable by unauthenticated users. The wordpress_object_type value is concatenated directly into a SQL query (post_type = "$object_type", class-object-sync-sf-wordpress.php:328) and executed via $wpdb->get_results() with no $wpdb->prepare() (:578). Because REST body parameters are not magic-quoted, an attacker can break out of the quoted string and inject arbitrary SQL. This makes it possible for unauthenticated attackers to append additional SQL queries (time-based blind), enabling extraction of sensitive information such as password hashes from the database. Only a valid wordpress_id (e.g. 1) is required — no authentication or Salesforce connection.