=1.1.0"}, "RULE-CAMPAIGN-LEARNPRESS-C-ONLY-FIELDS-SQLI-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/learnpress/v1/(courses|profile/course-tab)([/?&]|$)~i"}, {"name": "ARGS:c_only_fields", "type": "detectSQLi"}], "cve": "CAMPAIGN-2026-W18-LEARNPRESS-CFIELDS-SQLI", "description": "LearnPress \\u2014 block SQL injection attempts via the \'c_only_fields\' query\\nparameter on the REST endpoints /wp-json/learnpress/v1/courses and\\n/wp-json/learnpress/v1/profile/course-tab. The parameter is a column-name\\nprojection list; legitimate values are bare identifiers. SQL keywords or\\nfunction-call syntax in the value indicates injection.\\n", "mode": "block", "severity": 8.5, "slug": "learnpress", "tags": ["sql-injection", "rest-api", "unauthenticated"], "target": "plugin", "versions": ">=0"}, "RULE-CAMPAIGN-TRIBE-V1-EVENTS-STATUS-SQLI-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/tribe/events/v1/events([/?&]|$)~i"}, {"name": "ARGS:status", "type": "detectSQLi"}], "cve": "CAMPAIGN-2026-W18-TRIBE-STATUS-SQLI", "description": "The Events Calendar \\u2014 block SQL injection attempts via the \'status\' query\\nparameter on the REST endpoint /wp-json/tribe/events/v1/events. Complements\\nexisting coverage for the documented \'s\' parameter SQLi (CVE-2025-9807,\\nCVE-2025-12197) and \'order\' parameter SQLi (CVE-2024-8275).\\n", "mode": "block", "severity": 8.5, "slug": "the-events-calendar", "tags": ["sql-injection", "rest-api", "unauthenticated"], "target": "plugin", "versions": ">=0"}, "RULE-CVE-2015-10133-01": {"action": "init", "conditions": [{"name": "ARGS:wp-subscription-manager", "type": "equals", "value": "1"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2015-10133", "method": "GET", "mode": "block", "severity": 7.2, "slug": "subscribe-to-comments", "target": "plugin", "versions": "<=2.1.2"}, "RULE-CVE-2016-15033-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/wp-content/plugins/delete-all-comments/delete-all-comments\\\\.php~"}, {"name": "ARGS:restorefromfileNAME", "type": "exists"}, {"name": "ARGS:restorefromfileNAME", "type": "regex", "value": "~\\\\.(?:ph(?:p[0-9]?|s|tml?|t|ar)|s?html?|cgi|asp|aspx|jsp|jspx|cfm|user\\\\.ini)$|[\\\\\\\\/]\\\\.htaccess$|[\\\\\\\\/]\\\\.htpasswd$~i"}], "cve": "CVE-2016-15033", "description": "Delete All Comments <=2.0 unauthenticated arbitrary file upload via restorefromfileNAME", "mode": "block", "severity": 9.8, "slug": "delete-all-comments", "target": "plugin", "versions": "<=2.0"}, "RULE-CVE-2017-20192-01": {"ajax_action": "frm_forms_preview", "conditions": [{"name": "ARGS:after_html", "type": "regex", "value": "~(?:<\\\\s*script[\\\\s/>]|<\\\\s*(?:iframe|svg|img|body|object|embed|video|audio|source|link|meta|form|input|details|marquee)\\\\b[^>]*\\\\bon[a-z]+\\\\s*=|on(?:load|error|click|mouseover|focus|blur|submit|change|input|keydown|keyup|keypress|abort|toggle|animationstart|animationend)\\\\s*=|javascript\\\\s*:|data\\\\s*:\\\\s*[a-z0-9.+-]*\\\\s*[;,]?\\\\s*(?:base64|charset)|expression\\\\s*\\\\(|<\\\\s*style[^>]*>[^<]*expression|?0*(?:6[ad]|4[ad]|3c|2f);?|%3[Cc]\\\\s*script)~i"}], "cve": "CVE-2017-20192", "description": "Formidable Form Builder <2.05.03 unauthenticated stored XSS via after_html parameter in frm_forms_preview AJAX action", "mode": "block", "severity": 6.1, "slug": "formidable", "target": "plugin", "versions": "<2.05.03"}, "RULE-CVE-2017-20192-02": {"ajax_action": "frm_forms_preview", "conditions": [{"name": "ARGS:before_html", "type": "regex", "value": "~(?:<\\\\s*script[\\\\s/>]|<\\\\s*(?:iframe|svg|img|body|object|embed|video|audio|source|link|meta|form|input|details|marquee)\\\\b[^>]*\\\\bon[a-z]+\\\\s*=|on(?:load|error|click|mouseover|focus|blur|submit|change|input|keydown|keyup|keypress|abort|toggle|animationstart|animationend)\\\\s*=|javascript\\\\s*:|data\\\\s*:\\\\s*[a-z0-9.+-]*\\\\s*[;,]?\\\\s*(?:base64|charset)|expression\\\\s*\\\\(|<\\\\s*style[^>]*>[^<]*expression|?0*(?:6[ad]|4[ad]|3c|2f);?|%3[Cc]\\\\s*script)~i"}], "cve": "CVE-2017-20192", "description": "Formidable Form Builder <2.05.03 unauthenticated stored XSS via before_html parameter in frm_forms_preview AJAX action", "mode": "block", "severity": 6.1, "slug": "formidable", "target": "plugin", "versions": "<2.05.03"}, "RULE-CVE-2019-15319-01": {"action": "admin_init", "conditions": [{"name": "ARGS:import_data_textarea", "type": "regex", "value": "~^(?:Tzo|Qzo)[A-Za-z0-9+/=]{20,}~"}], "cve": "CVE-2019-15319", "description": "OptionTree <2.7.0 PHP Object Injection via import_data_textarea (base64-encoded unserialize)", "mode": "block", "severity": 9.8, "slug": "option-tree", "target": "plugin", "versions": "<2.7.0"}, "RULE-CVE-2019-15319-02": {"action": "admin_init", "conditions": [{"name": "ARGS:import_layouts", "type": "regex", "value": "~^(?:Tzo|Qzo)[A-Za-z0-9+/=]{20,}~"}], "cve": "CVE-2019-15319", "description": "OptionTree <2.7.0 PHP Object Injection via import_layouts (base64-encoded unserialize)", "mode": "block", "severity": 9.8, "slug": "option-tree", "target": "plugin", "versions": "<2.7.0"}, "RULE-CVE-2019-17237-01": {"ajax_action": "contact_form", "conditions": [{"name": "ARGS:contact_message", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur|submit)\\\\s*=|<(?:iframe|object|embed|form|img|svg|link|meta|base)[\\\\s/>]|javascript\\\\s*:)~i"}], "cve": "CVE-2019-17237", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2019-17237", "description": "IgniteUp <=3.4.3 CSRF + HTML injection in contact form email body via contact_message", "mode": "block", "severity": 8.8, "slug": "igniteup", "tags": ["xss", "html-injection", "csrf", "unauthenticated"], "target": "plugin", "versions": "<=3.4.3"}, "RULE-CVE-2019-17237-02": {"ajax_action": "contact_form", "conditions": [{"name": "ARGS:contact_subject", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur|submit)\\\\s*=|<(?:iframe|object|embed|form|img|svg|link|meta|base)[\\\\s/>]|javascript\\\\s*:|])~i"}], "cve": "CVE-2019-17237", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2019-17237", "description": "IgniteUp <=3.4.3 CSRF + HTML injection in contact form email subject via contact_subject", "mode": "block", "severity": 8.8, "slug": "igniteup", "tags": ["xss", "html-injection", "csrf", "unauthenticated"], "target": "plugin", "versions": "<=3.4.3"}, "RULE-CVE-2019-17237-03": {"ajax_action": "contact_form", "conditions": [{"name": "ARGS:contact_email", "type": "regex", "value": "~(?:%0[aAdD]|%0[aAdD]%0[aAdD]|\\\\r|\\\\n|\\\\r\\\\n)~"}], "cve": "CVE-2019-17237", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2019-17237", "description": "IgniteUp <=3.4.3 CSRF + email header injection via CRLF in contact_email", "mode": "block", "severity": 8.8, "slug": "igniteup", "tags": ["header-injection", "crlf-injection", "csrf", "unauthenticated"], "target": "plugin", "versions": "<=3.4.3"}, "RULE-CVE-2019-17237-04": {"ajax_action": "subscribe_email", "conditions": [{"name": "ARGS:cs_email", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/[*].*[*]/|\'\\\\s*(?:OR|AND)\\\\s+(?:\'?\\\\d|\'[^\']*\'\\\\s*=\\\\s*\')|--\\\\s*$|#\\\\s*(?:$|\\\\s))~i"}], "cve": "CVE-2019-17237", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2019-17237", "description": "IgniteUp <=3.4.3 CSRF + SQL injection in subscribe_email via cs_email parameter", "mode": "block", "severity": 8.8, "slug": "igniteup", "tags": ["sql-injection", "csrf", "unauthenticated"], "target": "plugin", "versions": "<=3.4.3"}, "RULE-CVE-2019-25214-01": {"ajax_action": "run_table_migration", "conditions": [{"name": "ARGS:action", "type": "equals", "value": "run_table_migration"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2019-25214", "method": "POST", "mode": "block", "severity": 6.1, "slug": "wpshopify", "target": "plugin", "versions": "<=2.0.4"}, "RULE-CVE-2019-25214-02": {"ajax_action": "run_table_migration", "conditions": [{"name": "ARGS:action", "type": "equals", "value": "run_table_migration"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2019-25214", "method": "GET", "mode": "block", "severity": 6.1, "slug": "wpshopify", "target": "plugin", "versions": "<=2.0.4"}, "RULE-CVE-2019-25217-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/siteground-optimizer/v1/switch-php(/|\\\\?|&|$)~"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2019-25217", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2019-25217", "description": "SG Optimizer <=5.0.12 unauthenticated PHP version switch via REST API", "method": "POST", "mode": "block", "severity": 9.8, "slug": "sg-cachepress", "tags": ["missing-authorization", "rest-api", "unauthenticated"], "target": "plugin", "versions": "<=5.0.12"}, "RULE-CVE-2019-25221-01": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin\\\\.php~"}, {"name": "ARGS:page", "type": "equals", "value": "responsive_portfolio_with_lightbox_media_management"}, {"name": "ARGS:id", "type": "detectSQLi"}], "cve": "CVE-2019-25221", "method": "GET", "mode": "block", "severity": 4.9, "slug": "responsive-filterable-portfolio", "target": "plugin", "versions": "<=1.0.8"}, "RULE-CVE-2019-25221-02": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin\\\\.php~"}, {"name": "ARGS:page", "type": "equals", "value": "responsive_portfolio_with_lightbox_media_management"}, {"name": "ARGS:media_type", "type": "detectSQLi"}], "cve": "CVE-2019-25221", "method": "POST", "mode": "block", "severity": 4.9, "slug": "responsive-filterable-portfolio", "target": "plugin", "versions": "<=1.0.8"}, "RULE-CVE-2019-25221-03": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin\\\\.php~"}, {"name": "ARGS:page", "type": "equals", "value": "responsive_portfolio_with_lightbox_media_management"}, {"name": "ARGS:id", "type": "regex", "value": "~(?:<[^>]*\\\\son\\\\w+\\\\s*=|<\\\\s*(?:script|iframe|object|embed|applet|base|link|meta|style|svg|math|body|video|audio|details|form|input|select|textarea|button|marquee)\\\\b|javascript\\\\s*:|vbscript\\\\s*:|data\\\\s*:[^,]*;base64)~i"}], "cve": "CVE-2019-25221", "method": "GET", "mode": "block", "severity": 4.9, "slug": "responsive-filterable-portfolio", "target": "plugin", "versions": "<=1.0.8"}, "RULE-CVE-2019-25221-04": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin\\\\.php~"}, {"name": "ARGS:page", "type": "equals", "value": "responsive_portfolio_with_lightbox_media_management"}, {"name": "ARGS:search_term", "type": "detectSQLi"}], "cve": "CVE-2019-25221", "method": "GET", "mode": "block", "severity": 4.9, "slug": "responsive-filterable-portfolio", "target": "plugin", "versions": "<=1.0.8"}, "RULE-CVE-2019-25221-05": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin\\\\.php~"}, {"name": "ARGS:page", "type": "equals", "value": "responsive_portfolio_with_lightbox_media_management"}, {"name": "ARGS:order_pos", "type": "detectSQLi"}], "cve": "CVE-2019-25221", "method": "GET", "mode": "block", "severity": 4.9, "slug": "responsive-filterable-portfolio", "target": "plugin", "versions": "<=1.0.8"}, "RULE-CVE-2019-25221-06": {"action": "admin_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin\\\\.php~"}, {"name": "ARGS:page", "type": "equals", "value": "responsive_portfolio_with_lightbox_media_management"}, {"name": "ARGS:order_by", "type": "detectSQLi"}], "cve": "CVE-2019-25221", "method": "GET", "mode": "block", "severity": 4.9, "slug": "responsive-filterable-portfolio", "target": "plugin", "versions": "<=1.0.8"}, "RULE-CVE-2020-13693-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-login\\\\.php~"}, {"name": "ARGS:bbp-forum-role", "type": "regex", "value": "~(?:bbp_keymaster|bbp_moderator|bbp_spectator)~i"}], "cve": "CVE-2020-13693", "description": "bbPress <2.6.5 unauthenticated privilege escalation via bbp-forum-role parameter on wp-login.php registration", "mode": "block", "severity": 9.8, "slug": "bbpress", "target": "plugin", "versions": "<2.6.5"}, "RULE-CVE-2020-13693-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-signup\\\\.php~"}, {"name": "ARGS:bbp-forum-role", "type": "regex", "value": "~(?:bbp_keymaster|bbp_moderator|bbp_spectator)~i"}], "cve": "CVE-2020-13693", "description": "bbPress <2.6.5 unauthenticated privilege escalation via bbp-forum-role parameter on wp-signup.php (multisite)", "mode": "block", "severity": 9.8, "slug": "bbpress", "target": "plugin", "versions": "<2.6.5"}, "RULE-CVE-2020-36730-01": {"ajax_action": "cmp_get_post_detail", "conditions": [{"name": "", "type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2020-36730", "description": "CMP Coming Soon and Maintenance <=3.8.1 missing authorization on cmp_get_post_detail AJAX handler", "mode": "block", "severity": 9.3, "slug": "cmp-coming-soon-maintenance", "target": "plugin", "versions": "<=3.8.1"}, "RULE-CVE-2020-36730-02": {"ajax_action": "niteo_export_csv", "conditions": [{"name": "", "type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2020-36730", "description": "CMP Coming Soon and Maintenance <=3.8.1 missing authorization on niteo_export_csv AJAX handler", "mode": "block", "severity": 9.3, "slug": "cmp-coming-soon-maintenance", "target": "plugin", "versions": "<=3.8.1"}, "RULE-CVE-2020-36730-03": {"ajax_action": "cmp_disable_comingsoon_ajax", "conditions": [{"name": "", "type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2020-36730", "description": "CMP Coming Soon and Maintenance <=3.8.1 missing authorization on cmp_disable_comingsoon_ajax AJAX handler", "mode": "block", "severity": 9.3, "slug": "cmp-coming-soon-maintenance", "target": "plugin", "versions": "<=3.8.1"}, "RULE-CVE-2020-36769-01": {"ajax_action": "import_widget_data", "conditions": [{"name": "ARGS:action", "type": "equals", "value": "import_widget_data"}, {"name": "ARGS:import_file", "type": "regex", "value": "~^https?://~i"}], "cve": "CVE-2020-36769", "method": "POST", "mode": "block", "severity": 5.4, "slug": "widget-settings-importexport", "target": "plugin", "versions": "<=1.5.3"}, "RULE-CVE-2020-36769-02": {"ajax_action": "import_widget_data", "conditions": [{"name": "ARGS:action", "type": "equals", "value": "import_widget_data"}, {"name": "ARGS:widgets", "type": "regex", "value": "~(?i)(<\\\\s*script\\\\b|javascript\\\\s*:|on\\\\w+\\\\s*=)~"}], "cve": "CVE-2020-36769", "method": "POST", "mode": "block", "severity": 5.4, "slug": "widget-settings-importexport", "target": "plugin", "versions": "<=1.5.3"}, "RULE-CVE-2020-36837-01": {"action": "admin_init", "conditions": [{"name": "ARGS:do_reset_wordpress", "type": "exists"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2020-36837", "method": "GET", "mode": "block", "severity": 9.9, "slug": "themegrill-demo-importer", "target": "plugin", "versions": ">=1.3.4 <=1.6.1"}, "RULE-CVE-2020-36838-01": {"ajax_action": "update_options", "conditions": [{"name": "ARGS:action", "type": "equals", "value": "update_options"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2020-36838", "method": "POST", "mode": "block", "severity": 7.4, "slug": "facebook-messenger-customer-chat", "target": "plugin", "versions": "<1.6"}, "RULE-CVE-2020-36842-01": {"ajax_action": "wpvivid_upload_import_files", "conditions": [{"name": "ARGS:action", "type": "equals", "value": "wpvivid_upload_import_files"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2020-36842", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2020-36842", "description": "WPvivid Backup/Restore <=0.9.35 missing capability check on wpvivid_upload_import_files AJAX action allows low-privilege authenticated arbitrary ZIP upload and extraction.", "method": "POST", "mode": "block", "severity": 8.8, "slug": "wpvivid-backuprestore", "tags": ["auth-arbitrary-file-upload", "missing-capability-check", "ajax"], "target": "plugin", "versions": "<=0.9.35"}, "RULE-CVE-2020-36842-02": {"ajax_action": "wpvivid_upload_files", "conditions": [{"name": "ARGS:action", "type": "equals", "value": "wpvivid_upload_files"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2020-36842", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2020-36842", "description": "WPvivid Backup/Restore <=0.9.35 missing capability check on wpvivid_upload_files AJAX action allows low-privilege authenticated arbitrary ZIP upload and extraction.", "method": "POST", "mode": "block", "severity": 8.8, "slug": "wpvivid-backuprestore", "tags": ["auth-arbitrary-file-upload", "missing-capability-check", "ajax"], "target": "plugin", "versions": "<=0.9.35"}, "RULE-CVE-2020-36848-01": {"ajax_action": "boldgrid_backup_download", "conditions": [{"name": "ARGS:file", "type": "regex", "value": "~(?:wp-config\\\\.php|/etc/passwd|\\\\.htaccess|\\\\.env|debug\\\\.log|error_log)~i"}], "cve": "CVE-2020-36848", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2020-36848", "description": "Total Upkeep by BoldGrid <=1.14.9 unauthenticated backup file download via boldgrid_backup_download AJAX action", "mode": "block", "severity": 7.5, "slug": "boldgrid-backup", "tags": ["information-disclosure", "unauthenticated", "broken-access-control"], "target": "plugin", "versions": "<=1.14.9"}, "RULE-CVE-2020-36848-02": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~/(?:cli/env-info\\\\.php|cron/restore-info\\\\.json)~"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2020-36848", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2020-36848", "description": "Total Upkeep by BoldGrid <=1.14.9 unauthenticated sensitive info exposure via direct access to env-info.php or restore-info.json (WordPress-routed requests only)", "mode": "block", "severity": 7.5, "slug": "boldgrid-backup", "tags": ["information-disclosure", "unauthenticated", "broken-access-control"], "target": "plugin", "versions": "<=1.14.9"}, "RULE-CVE-2020-7048-01": {"action": "init", "conditions": [{"name": "ARGS:db-reset-tables", "type": "exists"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2020-7048", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2020-7048", "description": "WP Database Reset <=3.1 unauthenticated database table reset via db-reset-tables[] parameter", "mode": "block", "severity": 9.1, "slug": "wordpress-database-reset", "tags": ["missing-authorization", "unauthenticated", "database-reset"], "target": "plugin", "versions": "<=3.1"}, "RULE-CVE-2020-9006-01": {"ajax_action": "import_popups", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2020-9006", "description": "Popup Builder <=2.6.7.6 missing authorization on import_popups allows subscriber+ SQL injection via PHP deserialization", "mode": "block", "severity": 9.8, "slug": "popup-builder", "target": "plugin", "versions": ">=2.2.8 <=2.6.7.6"}, "RULE-CVE-2020-9006-02": {"ajax_action": "import_popups", "conditions": [{"name": "ARGS:attachmentUrl", "type": "regex", "value": "~[OCa]:[0-9]+:[\\"\\\\{]~"}], "cve": "CVE-2020-9006", "description": "Popup Builder <=2.6.7.6 PHP object injection via attachmentUrl in import_popups AJAX handler", "mode": "block", "severity": 9.8, "slug": "popup-builder", "target": "plugin", "versions": ">=2.2.8 <=2.6.7.6"}, "RULE-CVE-2021-24209-01": {"action": "admin_init", "conditions": [{"name": "ARGS:page", "type": "equals", "value": "wpsupercache"}, {"name": "ARGS:wp_super_cache_location", "type": "regex", "value": "~(?:<\\\\?|\\\\?>|`|\\\\|\\\\s*\\\\w|;\\\\s*\\\\w|\\\\$\\\\(|(?:\\\\.\\\\.[\\\\\\\\/]){2,})~"}], "cve": "CVE-2021-24209", "description": "WP Super Cache <1.7.2 authenticated RCE via PHP code injection in cache path (wp_super_cache_location)", "mode": "block", "severity": 7.2, "slug": "wp-super-cache", "target": "plugin", "versions": "<1.7.2"}, "RULE-CVE-2021-24217-01": {"action": "admin_post_nopriv_wp_async_send_server_event", "conditions": [{"name": "ARGS:event_data", "type": "regex", "value": "~^(?:Tzo|Qzo)[A-Za-z0-9+/]~"}], "cve": "CVE-2021-24217", "description": "Facebook for WordPress <3.0.0 unauthenticated PHP object injection via event_data deserialization in async server event handler", "mode": "block", "severity": 8.1, "slug": "official-facebook-pixel", "target": "plugin", "versions": "<3.0.0"}, "RULE-CVE-2021-24217-02": {"action": "admin_post_wp_async_send_server_event", "conditions": [{"name": "ARGS:event_data", "type": "regex", "value": "~^(?:Tzo|Qzo)[A-Za-z0-9+/]~"}], "cve": "CVE-2021-24217", "description": "Facebook for WordPress <3.0.0 authenticated PHP object injection via event_data deserialization in async server event handler", "mode": "block", "severity": 8.1, "slug": "official-facebook-pixel", "target": "plugin", "versions": "<3.0.0"}, "RULE-CVE-2021-24280-01": {"ajax_action": "import_from_debug", "conditions": [{"name": "ARGS:data[debug_info]", "type": "regex", "value": "~(?:Tzo[0-9A-Za-z+/]|Qzo[0-9A-Za-z+/]|[A-Za-z0-9+/]*[OCa]:[0-9]+:[\\\\\\"\\\\\\\\{])~"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2021-24280", "description": "Redirection for Contact Form 7 <2.3.4 authenticated PHP object injection via import_from_debug AJAX action", "mode": "block", "severity": 8.8, "slug": "wpcf7-redirect", "target": "plugin", "versions": "<2.3.4"}, "RULE-CVE-2021-24376-01": {"ajax_action": "ao_ccss_import", "conditions": [{"name": "FILES:file:content", "type": "regex", "value": "~\\\\.(?:ph(?:p[0-9]?|s|tml?|t|ar)|s?html?|cgi|asp|aspx|jsp|jspx|cfm|user\\\\.ini)~i"}], "cve": "CVE-2021-24376", "description": "Autoptimize <2.7.8 authenticated RCE via malicious ZIP upload containing nested PHP files in Import Settings", "mode": "block", "severity": 9.8, "slug": "autoptimize", "target": "plugin", "versions": "<2.7.8"}, "RULE-CVE-2021-24376-02": {"ajax_action": "ao_ccss_import", "conditions": [{"name": "FILES:file:name", "type": "regex", "value": "~\\\\.(?:ph(?:p[0-9]?|s|tml?|t|ar)|s?html?|cgi|asp|aspx|jsp|jspx|cfm|user\\\\.ini)$~i"}], "cve": "CVE-2021-24376", "description": "Autoptimize <2.7.8 authenticated RCE via direct PHP file upload in Import Settings", "mode": "block", "severity": 9.8, "slug": "autoptimize", "target": "plugin", "versions": "<2.7.8"}, "RULE-CVE-2021-24584-01": {"ajax_action": "route_url", "conditions": [{"name": "ARGS:controller", "type": "equals", "value": "events"}, {"name": "ARGS:mptt_action", "type": "equals", "value": "update_event_data"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2021-24584", "method": "POST", "mode": "block", "severity": 5.4, "slug": "mp-timetable", "target": "plugin", "versions": "<=2.4.1"}, "RULE-CVE-2021-24585-01": {"ajax_action": "route_url", "conditions": [{"type": "missing_capability", "value": "manage_options"}, {"name": "ARGS:controller", "type": "equals", "value": "events"}, {"name": "ARGS:mptt_action", "type": "equals", "value": "get_event_data"}], "cve": "CVE-2021-24585", "mode": "block", "severity": 6.5, "slug": "mp-timetable", "target": "plugin", "versions": "<=2.3.19"}, "RULE-CVE-2021-24684-01": {"ajax_action": "_ping_import", "conditions": [{"name": "ARGS:pdf_file_id", "type": "exists"}, {"type": "missing_capability", "value": "edit_posts"}], "cve": "CVE-2021-24684", "description": "PDF Light Viewer <1.4.12 authenticated OS command injection via Ghostscript path in ping_import AJAX handler", "mode": "block", "severity": 8.8, "slug": "pdf-light-viewer", "target": "plugin", "versions": "<1.4.12"}, "RULE-CVE-2021-24849-01": {"ajax_action": "wcfm_ajax_controller", "conditions": [{"name": "ARGS:radius_lat", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|[\'\\"]\\\\s*(?:OR|AND)\\\\s+[\'\\"]|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\()~i"}], "cve": "CVE-2021-24849", "description": "Block SQL injection via wcfm_ajax_controller \\u2013 radius_lat parameter", "mode": "block", "severity": 9.8, "slug": "wc-multivendor-marketplace", "target": "plugin", "versions": "<3.4.12"}, "RULE-CVE-2021-24849-02": {"ajax_action": "wcfm_ajax_controller", "conditions": [{"name": "ARGS:radius_lng", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|[\'\\"]\\\\s*(?:OR|AND)\\\\s+[\'\\"]|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\()~i"}], "cve": "CVE-2021-24849", "description": "Block SQL injection via wcfm_ajax_controller \\u2013 radius_lng parameter", "mode": "block", "severity": 9.8, "slug": "wc-multivendor-marketplace", "target": "plugin", "versions": "<3.4.12"}, "RULE-CVE-2021-24849-03": {"ajax_action": "wcfm_ajax_controller", "conditions": [{"name": "ARGS:radius_range", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|[\'\\"]\\\\s*(?:OR|AND)\\\\s+[\'\\"]|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\()~i"}], "cve": "CVE-2021-24849", "description": "Block SQL injection via wcfm_ajax_controller \\u2013 radius_range parameter", "mode": "block", "severity": 9.8, "slug": "wc-multivendor-marketplace", "target": "plugin", "versions": "<3.4.12"}, "RULE-CVE-2021-24849-04": {"ajax_action": "wcfm_ajax_controller", "conditions": [{"name": "ARGS:radius_addr", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|[\'\\"]\\\\s*(?:OR|AND)\\\\s+[\'\\"]|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\()~i"}], "cve": "CVE-2021-24849", "description": "Block SQL injection via wcfm_ajax_controller \\u2013 radius_addr parameter", "mode": "block", "severity": 9.8, "slug": "wc-multivendor-marketplace", "target": "plugin", "versions": "<3.4.12"}, "RULE-CVE-2021-24849-05": {"ajax_action": "wcfm_ajax_controller", "conditions": [{"name": "ARGS:wcfmmp_store_search", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|[\'\\"]\\\\s*(?:OR|AND)\\\\s+[\'\\"]|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\()~i"}], "cve": "CVE-2021-24849", "description": "Block SQL injection via wcfm_ajax_controller \\u2013 wcfmmp_store_search parameter", "mode": "block", "severity": 9.8, "slug": "wc-multivendor-marketplace", "target": "plugin", "versions": "<3.4.12"}, "RULE-CVE-2021-24849-06": {"ajax_action": "wcfmmp_stores_list_search", "conditions": [{"name": "ARGS:wcfmmp_store_search", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|[\'\\"]\\\\s*(?:OR|AND)\\\\s+[\'\\"]|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\()~i"}], "cve": "CVE-2021-24849", "description": "Block SQL injection via wcfmmp_stores_list_search \\u2013 wcfmmp_store_search parameter", "mode": "block", "severity": 9.8, "slug": "wc-multivendor-marketplace", "target": "plugin", "versions": "<3.4.12"}, "RULE-CVE-2021-24862-01": {"action": "admin_init", "conditions": [{"name": "ARGS:action", "type": "equals", "value": "rm_chronos_ajax"}, {"name": "ARGS:task_ids", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|EXTRACTVALUE\\\\s*\\\\(|UPDATEXML\\\\s*\\\\(|LOAD_FILE\\\\s*\\\\(|INTO\\\\s+(?:OUT|DUMP)FILE|--|/\\\\*|#)~i"}], "cve": "CVE-2021-24862", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2021-24862", "description": "RegistrationMagic <5.0.1.6 authenticated SQL injection via rm_chronos_ajax action (task_ids scalar parameter, batch task duplication)", "mode": "block", "severity": 7.2, "slug": "custom-registration-form-builder-with-submission-manager", "tags": ["sql-injection", "authenticated"], "target": "plugin", "versions": "<5.0.1.6"}, "RULE-CVE-2021-24862-02": {"action": "admin_init", "conditions": [{"name": "ARGS:action", "type": "equals", "value": "rm_chronos_ajax"}, {"name": "ARGS:task_ids[0]", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|EXTRACTVALUE\\\\s*\\\\(|UPDATEXML\\\\s*\\\\(|LOAD_FILE\\\\s*\\\\(|INTO\\\\s+(?:OUT|DUMP)FILE|--|/\\\\*)~i"}], "cve": "CVE-2021-24862", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2021-24862", "description": "RegistrationMagic <5.0.1.6 authenticated SQL injection via rm_chronos_ajax action (task_ids array parameter, batch task duplication)", "mode": "block", "severity": 7.2, "slug": "custom-registration-form-builder-with-submission-manager", "tags": ["sql-injection", "authenticated"], "target": "plugin", "versions": "<5.0.1.6"}, "RULE-CVE-2021-24951-01": {"ajax_action": "learnpress_duplicate_post", "conditions": [{"name": "ARGS:id", "type": "regex", "value": "~(?:[\'\\");]|\\\\s+(?:OR|AND|UNION|SELECT|INSERT|UPDATE|DELETE|DROP)\\\\s|UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|(?:--|#)\\\\s|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|EXTRACTVALUE\\\\s*\\\\(|UPDATEXML\\\\s*\\\\()~i"}], "cve": "CVE-2021-24951", "description": "LearnPress <4.1.4 authenticated SQL injection via id parameter in course/lesson/quiz/question duplication AJAX handler", "mode": "block", "severity": 9.8, "slug": "learnpress", "target": "plugin", "versions": "<4.1.4"}, "RULE-CVE-2021-24959-01": {"ajax_action": "weu_selected_users_1", "conditions": [{"name": "ARGS:data_raw", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\bSLEEP\\\\s*\\\\(|EXTRACTVALUE\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|(?:AND|OR)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|/\\\\*[!+]|CONCAT\\\\s*\\\\()~i"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2021-24959", "description": "WP Email Users <=1.7.6 authenticated SQL injection via data_raw in weu_selected_users_1 AJAX action", "mode": "block", "severity": 8.8, "slug": "wp-email-users", "target": "plugin", "versions": "<=1.7.6"}, "RULE-CVE-2021-24959-02": {"ajax_action": "weu_send_mail_selected_users", "conditions": [{"name": "ARGS:subject", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\bSLEEP\\\\s*\\\\(|EXTRACTVALUE\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|(?:AND|OR)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|/\\\\*[!+]|CONCAT\\\\s*\\\\()~i"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2021-24959", "description": "WP Email Users <=1.7.6 authenticated SQL injection via subject in weu_send_mail_selected_users AJAX action", "mode": "block", "severity": 8.8, "slug": "wp-email-users", "target": "plugin", "versions": "<=1.7.6"}, "RULE-CVE-2021-24959-03": {"ajax_action": "weu_send_mail_selected_users", "conditions": [{"name": "ARGS:template_name", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\bSLEEP\\\\s*\\\\(|EXTRACTVALUE\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|(?:AND|OR)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|/\\\\*[!+]|CONCAT\\\\s*\\\\()~i"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2021-24959", "description": "WP Email Users <=1.7.6 authenticated SQL injection via template_name in weu_send_mail_selected_users AJAX action", "mode": "block", "severity": 8.8, "slug": "wp-email-users", "target": "plugin", "versions": "<=1.7.6"}, "RULE-CVE-2021-24994-01": {"ajax_action": "wpvivid_add_remote", "conditions": [{"name": "ARGS:remote", "type": "regex", "value": "~<(?:script|img|svg|iframe|embed|object|video|audio|body|input|details|math|marquee|a|div|p|table|form|base|link|meta|style|isindex|textarea|button|select|keygen)[^>a-zA-Z]|\\\\bon(?:error|load|click|mouseover|focus|blur|change|submit|reset|select|abort|beforeunload|hashchange|unload|resize|scroll|copy|cut|paste|drag|drop|play|seeking|toggle|wheel|pointer|animation|transition)\\\\s*=|javascript\\\\s*:|data\\\\s*:[^,]*text/html~i"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2021-24994", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2021-24994", "description": "WPvivid Backup & Migration <0.9.69 unauthenticated stored XSS via wpvivid_add_remote AJAX action (remote parameter)", "method": "POST", "mode": "block", "severity": 6.1, "slug": "wpvivid-backuprestore", "tags": ["xss", "stored-xss", "missing-authorization", "unauthenticated"], "target": "plugin", "versions": "<0.9.69"}, "RULE-CVE-2021-24994-02": {"ajax_action": "wpvivid_edit_remote", "conditions": [{"name": "ARGS:remote", "type": "regex", "value": "~<(?:script|img|svg|iframe|embed|object|video|audio|body|input|details|math|marquee|a|div|p|table|form|base|link|meta|style|isindex|textarea|button|select|keygen)[^>a-zA-Z]|\\\\bon(?:error|load|click|mouseover|focus|blur|change|submit|reset|select|abort|beforeunload|hashchange|unload|resize|scroll|copy|cut|paste|drag|drop|play|seeking|toggle|wheel|pointer|animation|transition)\\\\s*=|javascript\\\\s*:|data\\\\s*:[^,]*text/html~i"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2021-24994", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2021-24994", "description": "WPvivid Backup & Migration <0.9.69 unauthenticated stored XSS via wpvivid_edit_remote AJAX action (remote parameter)", "method": "POST", "mode": "block", "severity": 6.1, "slug": "wpvivid-backuprestore", "tags": ["xss", "stored-xss", "missing-authorization", "unauthenticated"], "target": "plugin", "versions": "<0.9.69"}, "RULE-CVE-2021-24994-03": {"ajax_action": "wpvivid_edit_remote", "conditions": [{"name": "ARGS:id", "type": "regex", "value": "~<(?:script|img|svg|iframe|embed|object|video|audio|body|input|details|math|marquee|a|div|p|table|form|base|link|meta|style|isindex|textarea|button|select|keygen)[^>a-zA-Z]|\\\\bon(?:error|load|click|mouseover|focus|blur|change|submit|reset|select|abort|beforeunload|hashchange|unload|resize|scroll|copy|cut|paste|drag|drop|play|seeking|toggle|wheel|pointer|animation|transition)\\\\s*=|javascript\\\\s*:|data\\\\s*:[^,]*text/html~i"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2021-24994", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2021-24994", "description": "WPvivid Backup & Migration <0.9.69 unauthenticated stored XSS via wpvivid_edit_remote AJAX action (id parameter)", "method": "POST", "mode": "block", "severity": 6.1, "slug": "wpvivid-backuprestore", "tags": ["xss", "stored-xss", "missing-authorization", "unauthenticated"], "target": "plugin", "versions": "<0.9.69"}, "RULE-CVE-2021-25052-01": {"action": "admin_init", "conditions": [{"name": "ARGS:page", "type": "equals", "value": "button-generation"}, {"name": "ARGS:tab", "type": "regex", "value": "~(?:(?:\\\\.\\\\.[\\\\\\\\/]){2,}|(?:data|https?|php|phar|expect|zip|ftp)://|(?:wp-config|/etc/passwd|\\\\.htaccess|\\\\.env))~i"}], "cve": "CVE-2021-25052", "description": "Button Generator <2.3.3 CSRF to RCE via arbitrary file inclusion in admin tab parameter", "mode": "block", "severity": 8.8, "slug": "button-generation", "target": "plugin", "versions": "<2.3.3"}, "RULE-CVE-2021-25082-01": {"ajax_action": "sgpb_autosave", "conditions": [{"name": "ARGS:allPopupData[sgpb_type]", "type": "regex", "value": "~(?:(?:\\\\.\\\\.[/\\\\\\\\]){2,}|(?:phar|php|data|expect|zip|glob|rar|ssh2|ogg|zlib|compress\\\\.zlib|compress\\\\.bzip2)://)~i"}], "cve": "CVE-2021-25082", "description": "Popup Builder < 4.0.7 - Local File Inclusion (LFI) via sgpb_type parameter in autosave AJAX handler", "mode": "block", "severity": 8.8, "slug": "popup-builder", "target": "plugin", "versions": "<4.0.7"}, "RULE-CVE-2021-34624-01": {"action": "init", "conditions": [{"name": "ARGS:action", "type": "equals", "value": "pp_registration"}, {"name": "FILES:profile_picture:name", "type": "regex", "value": "~\\\\.(?:ph(?:p[0-9]?|s|tml?|t|ar)|s?html?|cgi|asp|aspx|jsp|jspx|cfm|user\\\\.ini)$|[\\\\\\\\/]\\\\.htaccess$~i"}], "cve": "CVE-2021-34624", "description": "ProfilePress <=3.1.3 unauthenticated arbitrary file upload via registration profile_picture", "mode": "block", "severity": 9.8, "slug": "wp-user-avatar", "target": "plugin", "versions": ">=3.0.0 <=3.1.3"}, "RULE-CVE-2021-34624-03": {"action": "init", "conditions": [{"name": "ARGS:action", "type": "equals", "value": "pp_profile_update"}, {"name": "FILES:profile_picture:name", "type": "regex", "value": "~\\\\.(?:ph(?:p[0-9]?|s|tml?|t|ar)|s?html?|cgi|asp|aspx|jsp|jspx|cfm|user\\\\.ini)$|[\\\\\\\\/]\\\\.htaccess$~i"}], "cve": "CVE-2021-34624", "description": "ProfilePress <=3.1.3 subscriber+ arbitrary file upload via profile update profile_picture", "mode": "block", "severity": 9.8, "slug": "wp-user-avatar", "target": "plugin", "versions": ">=3.0.0 <=3.1.3"}, "RULE-CVE-2021-39317-01": {"ajax_action": "plugin_offline_installer", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2021-39317", "description": "Access Demo Importer <=1.0.6 subscriber+ arbitrary file upload and plugin activation via plugin_offline_installer AJAX action", "mode": "block", "severity": 8.8, "slug": "access-demo-importer", "target": "plugin", "versions": "<=1.0.6"}, "RULE-CVE-2021-39352-01": {"ajax_action": "ctdi_import_demo_data", "conditions": [{"name": "FILES:content_file:name", "type": "regex", "value": "~\\\\.(?:ph(?:p[0-9]?|s|tml?|t|ar)|s?html?|cgi|asp|aspx|jsp|jspx|cfm|user\\\\.ini)$|[\\\\\\\\/]\\\\.htaccess$|[\\\\\\\\/]\\\\.htpasswd$~i"}], "cve": "CVE-2021-39352", "description": "Catch Themes Demo Import <=1.7 authenticated arbitrary file upload via ctdi_import_demo_data AJAX handler", "mode": "block", "severity": 7.2, "slug": "catch-themes-demo-import", "target": "plugin", "versions": "<=1.7"}, "RULE-CVE-2021-4338-01": {"ajax_action": "jj4t3_redirect_form", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2021-4338", "description": "404 to 301 <=3.0.7 missing authorization on jj4t3_redirect_form AJAX action", "mode": "block", "severity": 5.4, "slug": "404-to-301", "target": "plugin", "versions": "<=3.0.7"}, "RULE-CVE-2021-4338-02": {"ajax_action": "jj4t3_redirect_thickbox", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2021-4338", "description": "404 to 301 <=3.0.7 missing authorization on jj4t3_redirect_thickbox AJAX action", "mode": "block", "severity": 5.4, "slug": "404-to-301", "target": "plugin", "versions": "<=3.0.7"}, "RULE-CVE-2021-4444-01": {"ajax_action": "woofilters_save", "conditions": [{"name": "ARGS:mod", "type": "equals", "value": "woofilters"}, {"name": "ARGS:filter_name", "type": "exists"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2021-4444", "method": "POST", "mode": "block", "severity": 7.3, "slug": "woo-product-filter", "target": "plugin", "versions": "<=1.4.9"}, "RULE-CVE-2021-4444-02": {"ajax_action": "woofilters_update", "conditions": [{"name": "ARGS:mod", "type": "equals", "value": "woofilters"}, {"name": "ARGS:id", "type": "exists"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2021-4444", "method": "POST", "mode": "block", "severity": 7.3, "slug": "woo-product-filter", "target": "plugin", "versions": "<=1.4.9"}, "RULE-CVE-2021-4444-03": {"ajax_action": "woofilters_delete", "conditions": [{"name": "ARGS:mod", "type": "equals", "value": "woofilters"}, {"name": "ARGS:id", "type": "exists"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2021-4444", "method": "POST", "mode": "block", "severity": 7.3, "slug": "woo-product-filter", "target": "plugin", "versions": "<=1.4.9"}, "RULE-CVE-2021-4446-01": {"ajax_action": "wpdeveloper_install_plugin", "conditions": [{"name": "ARGS:slug", "type": "exists"}, {"type": "missing_capability", "value": "install_plugins"}], "cve": "CVE-2021-4446", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2021-4446", "description": "Essential Addons for Elementor Lite <= 4.6.4 missing authorization on AJAX plugin installation via wpdeveloper_install_plugin, allowing low-privilege users to install arbitrary plugins.", "method": "POST", "mode": "block", "severity": 6.3, "slug": "essential-addons-for-elementor-lite", "tags": ["authz-bypass", "missing-capability-check", "wordpress-ajax"], "target": "plugin", "versions": "<=4.6.4"}, "RULE-CVE-2021-4446-02": {"ajax_action": "wpdeveloper_activate_plugin", "conditions": [{"name": "ARGS:basename", "type": "exists"}, {"type": "missing_capability", "value": "activate_plugins"}], "cve": "CVE-2021-4446", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2021-4446", "description": "Essential Addons for Elementor Lite <= 4.6.4 missing authorization on AJAX plugin activation via wpdeveloper_activate_plugin, enabling low-privilege users to activate installed plugins.", "method": "POST", "mode": "block", "severity": 6.3, "slug": "essential-addons-for-elementor-lite", "tags": ["authz-bypass", "missing-capability-check", "wordpress-ajax"], "target": "plugin", "versions": "<=4.6.4"}, "RULE-CVE-2021-4446-03": {"ajax_action": "wpdeveloper_upgrade_plugin", "conditions": [{"name": "ARGS:basename", "type": "exists"}, {"type": "missing_capability", "value": "update_plugins"}], "cve": "CVE-2021-4446", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2021-4446", "description": "Essential Addons for Elementor Lite <= 4.6.4 missing authorization on AJAX plugin upgrade via wpdeveloper_upgrade_plugin, enabling low-privilege users to trigger plugin upgrades.", "method": "POST", "mode": "block", "severity": 6.3, "slug": "essential-addons-for-elementor-lite", "tags": ["authz-bypass", "missing-capability-check", "wordpress-ajax"], "target": "plugin", "versions": "<=4.6.4"}, "RULE-CVE-2021-4450-01A": {"ajax_action": "post_grid_ajax_fetch_block_hub_by_id", "conditions": [{"name": "ARGS:meta_key", "type": "exists"}, {"name": "ARGS:meta_value", "type": "exists"}, {"name": "ARGS:meta_key", "type": "detectSQLi"}], "cve": "CVE-2021-4450", "method": "POST", "mode": "block", "severity": 8.8, "slug": "post-grid", "target": "plugin", "versions": "<=2.1.12"}, "RULE-CVE-2021-4450-01B": {"ajax_action": "post_grid_ajax_fetch_block_hub_by_id", "conditions": [{"name": "ARGS:meta_key", "type": "exists"}, {"name": "ARGS:meta_value", "type": "exists"}, {"name": "ARGS:meta_value", "type": "detectSQLi"}], "cve": "CVE-2021-4450", "method": "POST", "mode": "block", "severity": 8.8, "slug": "post-grid", "target": "plugin", "versions": "<=2.1.12"}, "RULE-CVE-2021-47933-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/api/flutter_woo/config[_-]file(?:/|\\\\?|$)~"}, {"name": "FILES:file:name", "type": "regex", "value": "~\\\\.(?:ph(?:p[0-9]?|s|tml?|t|ar)|s?html?|cgi|asp|aspx|jsp|jspx|cfm|(?:^|\\\\.)user\\\\.ini)$|[\\\\\\\\/]\\\\.htaccess$|[\\\\\\\\/]\\\\.htpasswd$~i"}], "cve": "CVE-2021-47933", "description": "MStore API <=2.0.6 unauthenticated arbitrary PHP file upload via REST config_file endpoint", "method": "POST", "mode": "block", "severity": 9.8, "slug": "mstore-api", "target": "plugin", "versions": "<=2.0.6"}, "RULE-CVE-2022-0320-01": {"ajax_action": "load_more", "conditions": [{"name": "ARGS:template_info[file_name]", "type": "regex", "value": "~(?:\\\\.\\\\.[\\\\\\\\/]){2,}|[a-z]+://~i"}], "cve": "CVE-2022-0320", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2022-0320", "description": "Essential Addons for Elementor <=5.0.4 unauthenticated LFI via load_more templateInfo[file_name]", "mode": "block", "severity": 9.8, "slug": "essential-addons-for-elementor-lite", "tags": ["local-file-inclusion", "path-traversal", "unauthenticated"], "target": "plugin", "versions": "<=5.0.4"}, "RULE-CVE-2022-0320-02": {"ajax_action": "load_more", "conditions": [{"name": "ARGS:template_info[name]", "type": "regex", "value": "~(?:\\\\.\\\\.[\\\\\\\\/]){2,}|[a-z]+://~i"}], "cve": "CVE-2022-0320", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2022-0320", "description": "Essential Addons for Elementor <=5.0.4 unauthenticated LFI via load_more template_info[name]", "mode": "block", "severity": 9.8, "slug": "essential-addons-for-elementor-lite", "tags": ["local-file-inclusion", "path-traversal", "unauthenticated"], "target": "plugin", "versions": "<=5.0.4"}, "RULE-CVE-2022-0320-03": {"ajax_action": "woo_product_pagination_product", "conditions": [{"name": "ARGS:templateInfo[file_name]", "type": "regex", "value": "~(?:\\\\.\\\\.[\\\\\\\\/]){2,}|[a-z]+://~i"}], "cve": "CVE-2022-0320", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2022-0320", "description": "Essential Addons for Elementor <=5.0.4 unauthenticated LFI via woo_product_pagination_product templateInfo[file_name]", "mode": "block", "severity": 9.8, "slug": "essential-addons-for-elementor-lite", "tags": ["local-file-inclusion", "path-traversal", "unauthenticated"], "target": "plugin", "versions": "<=5.0.4"}, "RULE-CVE-2022-0320-04": {"ajax_action": "woo_product_pagination_product", "conditions": [{"name": "ARGS:templateInfo[name]", "type": "regex", "value": "~(?:\\\\.\\\\.[\\\\\\\\/]){2,}|[a-z]+://~i"}], "cve": "CVE-2022-0320", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2022-0320", "description": "Essential Addons for Elementor <=5.0.4 unauthenticated LFI via woo_product_pagination_product templateInfo[name]", "mode": "block", "severity": 9.8, "slug": "essential-addons-for-elementor-lite", "tags": ["local-file-inclusion", "path-traversal", "unauthenticated"], "target": "plugin", "versions": "<=5.0.4"}, "RULE-CVE-2022-0320-05": {"ajax_action": "woo_product_pagination", "conditions": [{"name": "ARGS:template_info[file_name]", "type": "regex", "value": "~(?:\\\\.\\\\.[\\\\\\\\/]){2,}|[a-z]+://~i"}], "cve": "CVE-2022-0320", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2022-0320", "description": "Essential Addons for Elementor <=5.0.4 unauthenticated LFI via woo_product_pagination template_info[file_name]", "mode": "block", "severity": 9.8, "slug": "essential-addons-for-elementor-lite", "tags": ["local-file-inclusion", "path-traversal", "unauthenticated"], "target": "plugin", "versions": "<=5.0.4"}, "RULE-CVE-2022-0320-06": {"ajax_action": "woo_product_pagination", "conditions": [{"name": "ARGS:template_info[name]", "type": "regex", "value": "~(?:\\\\.\\\\.[\\\\\\\\/]){2,}|[a-z]+://~i"}], "cve": "CVE-2022-0320", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2022-0320", "description": "Essential Addons for Elementor <=5.0.4 unauthenticated LFI via woo_product_pagination template_info[name]", "mode": "block", "severity": 9.8, "slug": "essential-addons-for-elementor-lite", "tags": ["local-file-inclusion", "path-traversal", "unauthenticated"], "target": "plugin", "versions": "<=5.0.4"}, "RULE-CVE-2022-0439-01": {"ajax_action": "ajax_fetch_report_list", "conditions": [{"name": "ARGS:order", "type": "exists"}, {"name": "ARGS:order", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|(?:ELT|MAKE_SET|EXTRACTVALUE|UPDATEXML)\\\\s*\\\\(|IF\\\\s*\\\\(|CASE\\\\s+WHEN\\\\s.*\\\\s+THEN\\\\s)~i"}], "cve": "CVE-2022-0439", "description": "Email Subscribers & Newsletters < 5.3.2 - Blind SQL Injection via ajax_fetch_report_list (order param)", "mode": "block", "severity": 8.8, "slug": "email-subscribers", "target": "plugin", "versions": "<5.3.2"}, "RULE-CVE-2022-0439-02": {"ajax_action": "ajax_fetch_report_list", "conditions": [{"name": "ARGS:orderby", "type": "exists"}, {"name": "ARGS:orderby", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|(?:ELT|MAKE_SET|EXTRACTVALUE|UPDATEXML)\\\\s*\\\\(|IF\\\\s*\\\\(|CASE\\\\s+WHEN\\\\s.*\\\\s+THEN\\\\s)~i"}], "cve": "CVE-2022-0439", "description": "Email Subscribers & Newsletters < 5.3.2 - Blind SQL Injection via ajax_fetch_report_list (orderby param)", "mode": "block", "severity": 8.8, "slug": "email-subscribers", "target": "plugin", "versions": "<5.3.2"}, "RULE-CVE-2022-0441-01": {"ajax_action": "stm_lms_register", "conditions": [{"name": "ARGS:register_as", "type": "regex", "value": "~^(?!(?:student|instructor)$).+~i"}], "cve": "CVE-2022-0441", "description": "MasterStudy LMS <2.7.6 unauthenticated privilege escalation via register_as parameter in stm_lms_register", "mode": "block", "severity": 9.8, "slug": "masterstudy-lms-learning-management-system", "target": "plugin", "versions": "<2.7.6"}, "RULE-CVE-2022-0531-01A": {"action": "admin_menu", "conditions": [{"name": "ARGS:page", "type": "regex", "value": "~^(?i)wpvivid$~"}, {"name": "ARGS:sub_page", "type": "regex", "value": "~[\\"\'<>]~"}], "cve": "CVE-2022-0531", "method": "GET", "mode": "block", "severity": 6.1, "slug": "wpvivid-backuprestore", "target": "plugin", "versions": "<=0.9.69"}, "RULE-CVE-2022-0531-01B": {"action": "admin_menu", "conditions": [{"name": "ARGS:page", "type": "regex", "value": "~^(?i)wpvivid$~"}, {"name": "ARGS:sub_tab", "type": "regex", "value": "~[\\"\'<>]~"}], "cve": "CVE-2022-0531", "method": "GET", "mode": "block", "severity": 6.1, "slug": "wpvivid-backuprestore", "target": "plugin", "versions": "<=0.9.69"}, "RULE-CVE-2022-0693-01": {"ajax_action": "remove_post_meta_condition", "conditions": [{"name": "ARGS:meta_ids", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE|CREATE|ALTER|TRUNCATE)\\\\s|\\\\b(?:AND|OR)\\\\s+[\\"\'\\\\d].*?[=<>]|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|WAITFOR\\\\s+DELAY|extractvalue\\\\s*\\\\(|updatexml\\\\s*\\\\(|EXP\\\\s*\\\\(\\\\s*SELECT|FLOOR\\\\s*\\\\(\\\\s*RAND|/\\\\*[!+]|(?:--|#)\\\\s)~i"}], "cve": "CVE-2022-0693", "description": "Master Elements <=8.0 unauthenticated SQL injection via meta_ids in remove_post_meta_condition AJAX handler", "mode": "block", "severity": 9.8, "slug": "master-elements", "target": "plugin", "versions": "<=8.0"}, "RULE-CVE-2022-1565-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~[/\\\\\\\\]wp_all_import_get_gz\\\\.php~i"}, {"name": "ARGS:name", "type": "regex", "value": "~\\\\.(?:ph(?:p[0-9]?|s|tml?|t|ar)|s?html?|cgi|asp|aspx|jsp|user\\\\.ini)(?:[?#]|$)|[\\\\\\\\/]\\\\.htaccess(?:[?#]|$)~i"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2022-1565", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2022-1565", "description": "WP All Import <=3.6.7 authenticated arbitrary PHP file upload via wp_all_import_get_gz.php name parameter", "mode": "block", "severity": 7.2, "slug": "wp-all-import", "tags": ["arbitrary-file-upload", "remote-code-execution", "authenticated"], "target": "plugin", "versions": "<=3.6.7"}, "RULE-CVE-2022-1565-02": {"ajax_action": "pmxi_upload_file", "conditions": [{"name": "FILES:file:name", "type": "regex", "value": "~\\\\.(?:ph(?:p[0-9]?|s|tml?|t|ar)|s?html?|cgi|asp|aspx|jsp|user\\\\.ini)(?:[?#]|$)|[\\\\\\\\/]\\\\.htaccess(?:[?#]|$)~i"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2022-1565", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2022-1565", "description": "WP All Import <=3.6.7 authenticated arbitrary PHP file upload via pmxi_upload_file AJAX action", "mode": "block", "severity": 7.2, "slug": "wp-all-import", "tags": ["arbitrary-file-upload", "remote-code-execution", "authenticated"], "target": "plugin", "versions": "<=3.6.7"}, "RULE-CVE-2022-1574-01": {"ajax_action": "html_actions", "conditions": [{"name": "FILES:html_import_file:name", "type": "regex", "value": "~\\\\.(?:ph(?:p[0-9]?|s|tml?|t|ar)|s(?:html?|htm)|cgi|asp|aspx|jsp|jspx|cfm|user\\\\.ini)$|\\\\.htaccess$|\\\\.htpasswd$~i"}], "cve": "CVE-2022-1574", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2022-1574", "description": "HTML2WP <=1.0.0 subscriber+ arbitrary file upload via html_actions AJAX handler", "mode": "block", "severity": 9.8, "slug": "html2wp", "tags": ["arbitrary-file-upload", "missing-authorization", "unauthenticated"], "target": "plugin", "versions": "<=1.0.0"}, "RULE-CVE-2022-1574-02": {"ajax_action": "html_actions", "conditions": [{"name": "ARGS:path", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2022-1574", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2022-1574", "description": "HTML2WP <=1.0.0 subscriber+ reflected XSS via path parameter in html_actions AJAX handler", "mode": "block", "severity": 9.8, "slug": "html2wp", "tags": ["xss", "reflected", "missing-authorization"], "target": "plugin", "versions": "<=1.0.0"}, "RULE-CVE-2022-1574-03": {"ajax_action": "html_actions", "conditions": [{"name": "ARGS:path", "type": "regex", "value": "~(?:(?:\\\\.\\\\.[\\\\\\\\/]){2,}|(?:wp-config\\\\.php|/etc/passwd|\\\\.htaccess|\\\\.env|debug\\\\.log))~i"}], "cve": "CVE-2022-1574", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2022-1574", "description": "HTML2WP <=1.0.0 subscriber+ arbitrary file read/delete via path parameter in html_actions AJAX handler", "mode": "block", "severity": 9.8, "slug": "html2wp", "tags": ["path-traversal", "arbitrary-file-read", "missing-authorization"], "target": "plugin", "versions": "<=1.0.0"}, "RULE-CVE-2022-1577-01": {"ajax_action": "save_backup_time", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2022-1577", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2022-1577", "description": "Database Backup for WordPress <2.5.2 CSRF and missing authorization on save_backup_time allows unauthorized schedule modification", "mode": "block", "severity": 5.4, "slug": "wp-db-backup", "tags": ["csrf", "missing-authorization", "schedule-modification"], "target": "plugin", "versions": "<2.5.2"}, "RULE-CVE-2022-1707-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~[?&]s=~"}, {"name": "ARGS:s", "type": "regex", "value": "~<(?:script|img|object|iframe|embed|svg)[^>]*>|javascript:|on(?:error|load|click|mouseover)\\\\s*=~i"}], "cve": "CVE-2022-1707", "description": "Google Tag Manager for WordPress <=1.15 reflected XSS via s parameter", "mode": "block", "severity": 6.1, "slug": "duracelltomi-google-tag-manager", "target": "plugin", "versions": "<=1.15"}, "RULE-CVE-2022-1768-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|[?&])rest_route=)/rsvpmaker/v1/stripesuccess(?:/[^/?]*)?(?:[/?&]|$)~"}, {"name": "ARGS:rsvp_id", "type": "regex", "value": "~(?i)(?:\'\\\\s*(?:OR|AND)\\\\b|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|UNION(?:\\\\s+ALL)?\\\\s+SELECT|SELECT(?:\\\\s|\\\\()|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|EXTRACTVALUE\\\\s*\\\\(|UPDATEXML\\\\s*\\\\(|pg_sleep\\\\s*\\\\(|WAITFOR\\\\s+DELAY|information_schema|LOAD_FILE\\\\s*\\\\(|INTO\\\\s+(?:OUT|DUMP)FILE|--\\\\s*$|/\\\\*|;\\\\s*(?:DROP|ALTER|INSERT|UPDATE|DELETE)\\\\b)~"}], "cve": "CVE-2022-1768", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2022-1768", "description": "RSVPMaker <=9.3.2 unauthenticated time-based blind SQL injection via rsvp_id parameter in REST route /wp-json/rsvpmaker/v1/stripesuccess/ (confirmed in production, 190/200 proactive_queue samples targeted this endpoint with SLEEP() payloads)", "method": "POST", "mode": "block", "severity": 9.8, "slug": "rsvpmaker", "tags": ["sql-injection", "unauthenticated", "rest-api", "time-based-blind", "prod-evidence"], "target": "plugin", "versions": "<=9.3.2"}, "RULE-CVE-2022-1768-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|[?&])rest_route=)/rsvpmaker/v1/stripesuccess(?:/[^/?]*)?(?:[/?&]|$)~"}, {"name": "ARGS:rsvp_id", "type": "regex", "value": "~(?i)(?:\'\\\\s*(?:OR|AND)\\\\b|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|UNION(?:\\\\s+ALL)?\\\\s+SELECT|SELECT(?:\\\\s|\\\\()|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|EXTRACTVALUE\\\\s*\\\\(|UPDATEXML\\\\s*\\\\(|pg_sleep\\\\s*\\\\(|WAITFOR\\\\s+DELAY|information_schema|LOAD_FILE\\\\s*\\\\(|INTO\\\\s+(?:OUT|DUMP)FILE|--\\\\s*$|/\\\\*|;\\\\s*(?:DROP|ALTER|INSERT|UPDATE|DELETE)\\\\b)~"}], "cve": "CVE-2022-1768", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2022-1768", "description": "RSVPMaker <=9.3.2 unauthenticated time-based blind SQL injection via rsvp_id parameter in REST route /wp-json/rsvpmaker/v1/stripesuccess/ (GET variant)", "method": "GET", "mode": "block", "severity": 9.8, "slug": "rsvpmaker", "tags": ["sql-injection", "unauthenticated", "rest-api", "time-based-blind", "prod-evidence"], "target": "plugin", "versions": "<=9.3.2"}, "RULE-CVE-2022-1768-03": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|[?&])rest_route=)/rsvpmaker/v1/sked(?:/[^/?]*)?(?:[/?&]|$)~"}, {"name": "ARGS:post_id", "type": "regex", "value": "~(?i)(?:\'\\\\s*(?:OR|AND)\\\\b|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|UNION(?:\\\\s+ALL)?\\\\s+SELECT|SELECT(?:\\\\s|\\\\()|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|EXTRACTVALUE\\\\s*\\\\(|UPDATEXML\\\\s*\\\\(|pg_sleep\\\\s*\\\\(|WAITFOR\\\\s+DELAY|information_schema|LOAD_FILE\\\\s*\\\\(|INTO\\\\s+(?:OUT|DUMP)FILE|--\\\\s*$|/\\\\*|;\\\\s*(?:DROP|ALTER|INSERT|UPDATE|DELETE)\\\\b)~"}], "cve": "CVE-2022-1768", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2022-1768", "description": "RSVPMaker <=9.3.2 unauthenticated time-based blind SQL injection via post_id parameter in REST route /wp-json/rsvpmaker/v1/sked/{id} (secondary sink from reference digest, Week 15 2026)", "mode": "block", "severity": 9.8, "slug": "rsvpmaker", "tags": ["sql-injection", "unauthenticated", "rest-api", "time-based-blind"], "target": "plugin", "versions": "<=9.3.2"}, "RULE-CVE-2022-1985-01": {"action": "init", "conditions": [{"name": "ARGS:frameid", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:)~i"}], "cve": "CVE-2022-1985", "description": "Download Manager <=3.2.42 reflected XSS via frameid parameter in shortcode-iframe.php", "mode": "block", "severity": 6.1, "slug": "download-manager", "target": "plugin", "versions": "<=3.2.42"}, "RULE-CVE-2022-2314-01": {"action": "init", "conditions": [{"name": "ARGS:vrc_cmd", "type": "exists"}], "cve": "CVE-2022-2314", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2022-2314", "description": "VR Calendar <=2.3.2 unauthenticated arbitrary PHP function execution via vrc_cmd parameter", "mode": "block", "severity": 9.8, "slug": "vr-calendar-sync", "tags": ["code-execution", "unauthenticated", "missing-authorization"], "target": "plugin", "versions": "<=2.3.2"}, "RULE-CVE-2022-2314-02": {"action": "init", "conditions": [{"name": "ARGS:action", "type": "equals", "value": "getSingleCalendarCustome"}, {"name": "ARGS:id", "type": "regex", "value": "~.+~"}], "cve": "CVE-2022-2314", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2022-2314", "description": "VR Calendar <=2.3.1 unauthenticated information disclosure via getSingleCalendarCustome AJAX handler", "mode": "block", "severity": 9.8, "slug": "vr-calendar-sync", "tags": ["information-disclosure", "unauthenticated", "missing-authorization"], "target": "plugin", "versions": "<2.3.2"}, "RULE-CVE-2022-2431-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/post\\\\.php~"}, {"name": "ARGS:post_type", "type": "equals", "value": "wpdmpro"}, {"name": "ARGS", "type": "regex", "value": "~(?:(?:\\\\.\\\\.[\\\\\\\\/]){2,}|(?:^|[\\\\\\\\/])(?:wp-config\\\\.php|\\\\.htaccess|\\\\.env)|[\\\\\\\\/]etc[\\\\\\\\/]passwd)~i"}], "cve": "CVE-2022-2431", "description": "Download Manager <=3.2.50 authenticated (contributor+) arbitrary file deletion via path traversal in file[files][] parameter", "mode": "block", "severity": 8.8, "slug": "download-manager", "target": "plugin", "versions": "<=3.2.50"}, "RULE-CVE-2022-2434-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~[?&]page=string-locator~"}, {"name": "ARGS:string-locator-path", "type": "regex", "value": "~(?:^|(?:%0[aAdD]|\\\\s))(?:phar|zip|compress\\\\.zlib|php|data|expect|glob)(?:%3[Aa]|:)//~i"}], "cve": "CVE-2022-2434", "description": "String Locator <=2.5.0 PHAR deserialization via string-locator-path parameter on editor page", "mode": "block", "severity": 8.8, "slug": "string-locator", "target": "plugin", "versions": "<=2.5.0"}, "RULE-CVE-2022-2439-01": {"ajax_action": "ime_test_im_path", "conditions": [{"name": "ARGS:cli_path", "type": "regex", "value": "~[;|&`$(){}\\\\n\\\\r<>]|\\\\$\\\\(~"}], "cve": "CVE-2022-2439", "method": "POST", "mode": "block", "severity": 7.2, "slug": "imagemagick-engine", "target": "plugin", "versions": "<1.7.5"}, "RULE-CVE-2022-2446-01": {"ajax_action": "wpeditor_browse_theme_root", "conditions": [{"name": "ARGS:current_theme_root", "type": "regex", "value": "~^phar://~i"}], "cve": "CVE-2022-2446", "method": "POST", "mode": "block", "severity": 7.2, "slug": "wp-editor", "target": "plugin", "versions": "<=1.2.9"}, "RULE-CVE-2022-2446-02": {"ajax_action": "wpeditor_get_file", "conditions": [{"name": "ARGS:file_path", "type": "regex", "value": "~^phar://~i"}], "cve": "CVE-2022-2446", "method": "POST", "mode": "block", "severity": 7.2, "slug": "wp-editor", "target": "plugin", "versions": "<=1.2.9"}, "RULE-CVE-2022-2446-03": {"ajax_action": "wpeditor_upload", "conditions": [{"name": "ARGS:complete_directory", "type": "regex", "value": "~^phar://~i"}], "cve": "CVE-2022-2446", "method": "POST", "mode": "block", "severity": 7.2, "slug": "wp-editor", "target": "plugin", "versions": "<=1.2.9"}, "RULE-CVE-2022-2446-04": {"ajax_action": "wpeditor_save_file", "conditions": [{"name": "ARGS:real_file", "type": "regex", "value": "~^phar://~i"}], "cve": "CVE-2022-2446", "method": "POST", "mode": "block", "severity": 7.2, "slug": "wp-editor", "target": "plugin", "versions": "<=1.2.9"}, "RULE-CVE-2022-25148-03": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/wp-statistics/v2/hit(?:[/?&]|$)~"}, {"name": "ARGS:ip", "type": "regex", "value": "~(?:\'\\\\s*(?:OR|AND|UNION|SELECT|SLEEP|BENCHMARK|IF|CASE|--|;|/\\\\*)|UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s)~i"}], "cve": "CVE-2022-25148", "description": "WP Statistics <=13.1.5 unauthenticated SQL injection via ip parameter in REST hit endpoint", "mode": "block", "severity": 9.8, "slug": "wp-statistics", "target": "plugin", "versions": "<=13.1.5"}, "RULE-CVE-2022-3384-01": {"ajax_action": "um_populate_dropdown_options", "conditions": [{"name": "ARGS:option_value", "type": "regex", "value": "~^(?:phpinfo|system|exec|shell_exec|passthru|popen|proc_open|curl_exec|curl_multi_exec|parse_str|create_function|assert|preg_replace|e(?:val)?\\\\(|call_user_func(?:_array)?)\\\\s*\\\\(~i"}], "cve": "CVE-2022-3384", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2022-3384", "description": "Ultimate Member <=2.5.0 authenticated RCE via populate_dropdown_options callback parameter", "mode": "block", "severity": 7.2, "slug": "ultimate-member", "tags": ["rce", "code-execution", "authenticated"], "target": "plugin", "versions": "<=2.5.0"}, "RULE-CVE-2022-33965-01": {"ajax_action": "liveStats", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?i)(?:[\'\\"`]\\\\s*(?:OR|AND)\\\\s+[\'\\"`\\\\d]|\\\\bUNION\\\\b\\\\s+(?:ALL\\\\s+)?\\\\bSELECT\\\\b\\\\s+(?:[0-9]|NULL\\\\b|@@|0x|CONCAT|CHAR)|\\\\bSLEEP\\\\s*[(]|\\\\bBENCHMARK\\\\s*[(]|\\\\bEXTRACTVALUE\\\\s*[(]|\\\\bUPDATEXML\\\\s*[(]|/[*][!*]|;\\\\s*(?:DROP|ALTER|CREATE|TRUNCATE)\\\\b)~"}], "cve": "CVE-2022-33965", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2022-33965", "description": "WP Visitor Statistics <=5.7 unauthenticated SQL injection via liveStats AJAX action", "method": "POST", "mode": "block", "severity": 9.8, "slug": "wp-stats-manager", "tags": ["sql-injection", "unauthenticated", "ajax"], "target": "plugin", "versions": "<=5.7"}, "RULE-CVE-2022-33965-02": {"ajax_action": "refDetails", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?i)(?:[\'\\"`]\\\\s*(?:OR|AND)\\\\s+[\'\\"`\\\\d]|\\\\bUNION\\\\b\\\\s+(?:ALL\\\\s+)?\\\\bSELECT\\\\b\\\\s+(?:[0-9]|NULL\\\\b|@@|0x|CONCAT|CHAR)|\\\\bSLEEP\\\\s*[(]|\\\\bBENCHMARK\\\\s*[(]|\\\\bEXTRACTVALUE\\\\s*[(]|\\\\bUPDATEXML\\\\s*[(]|/[*][!*]|;\\\\s*(?:DROP|ALTER|CREATE|TRUNCATE)\\\\b)~"}], "cve": "CVE-2022-33965", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2022-33965", "description": "WP Visitor Statistics <=5.7 unauthenticated SQL injection via refDetails AJAX action", "method": "POST", "mode": "block", "severity": 9.8, "slug": "wp-stats-manager", "tags": ["sql-injection", "unauthenticated", "ajax"], "target": "plugin", "versions": "<=5.7"}, "RULE-CVE-2022-33965-03": {"ajax_action": "getDateWiseLocationDetail", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?i)(?:[\'\\"`]\\\\s*(?:OR|AND)\\\\s+[\'\\"`\\\\d]|\\\\bUNION\\\\b\\\\s+(?:ALL\\\\s+)?\\\\bSELECT\\\\b\\\\s+(?:[0-9]|NULL\\\\b|@@|0x|CONCAT|CHAR)|\\\\bSLEEP\\\\s*[(]|\\\\bBENCHMARK\\\\s*[(]|\\\\bEXTRACTVALUE\\\\s*[(]|\\\\bUPDATEXML\\\\s*[(]|/[*][!*]|;\\\\s*(?:DROP|ALTER|CREATE|TRUNCATE)\\\\b)~"}], "cve": "CVE-2022-33965", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2022-33965", "description": "WP Visitor Statistics <=5.7 unauthenticated SQL injection via getDateWiseLocationDetail AJAX action", "method": "POST", "mode": "block", "severity": 9.8, "slug": "wp-stats-manager", "tags": ["sql-injection", "unauthenticated", "ajax"], "target": "plugin", "versions": "<=5.7"}, "RULE-CVE-2022-33965-04": {"ajax_action": "getContentUrlDayView", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?i)(?:[\'\\"`]\\\\s*(?:OR|AND)\\\\s+[\'\\"`\\\\d]|\\\\bUNION\\\\b\\\\s+(?:ALL\\\\s+)?\\\\bSELECT\\\\b\\\\s+(?:[0-9]|NULL\\\\b|@@|0x|CONCAT|CHAR)|\\\\bSLEEP\\\\s*[(]|\\\\bBENCHMARK\\\\s*[(]|\\\\bEXTRACTVALUE\\\\s*[(]|\\\\bUPDATEXML\\\\s*[(]|/[*][!*]|;\\\\s*(?:DROP|ALTER|CREATE|TRUNCATE)\\\\b)~"}], "cve": "CVE-2022-33965", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2022-33965", "description": "WP Visitor Statistics <=5.7 unauthenticated SQL injection via getContentUrlDayView AJAX action", "method": "POST", "mode": "block", "severity": 9.8, "slug": "wp-stats-manager", "tags": ["sql-injection", "unauthenticated", "ajax"], "target": "plugin", "versions": "<=5.7"}, "RULE-CVE-2022-33965-05": {"ajax_action": "getReferralOSDetails", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?i)(?:[\'\\"`]\\\\s*(?:OR|AND)\\\\s+[\'\\"`\\\\d]|\\\\bUNION\\\\b\\\\s+(?:ALL\\\\s+)?\\\\bSELECT\\\\b\\\\s+(?:[0-9]|NULL\\\\b|@@|0x|CONCAT|CHAR)|\\\\bSLEEP\\\\s*[(]|\\\\bBENCHMARK\\\\s*[(]|\\\\bEXTRACTVALUE\\\\s*[(]|\\\\bUPDATEXML\\\\s*[(]|/[*][!*]|;\\\\s*(?:DROP|ALTER|CREATE|TRUNCATE)\\\\b)~"}], "cve": "CVE-2022-33965", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2022-33965", "description": "WP Visitor Statistics <=5.7 unauthenticated SQL injection via getReferralOSDetails AJAX action", "method": "POST", "mode": "block", "severity": 9.8, "slug": "wp-stats-manager", "tags": ["sql-injection", "unauthenticated", "ajax"], "target": "plugin", "versions": "<=5.7"}, "RULE-CVE-2022-33965-06": {"ajax_action": "refUrlDetails", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?i)(?:[\'\\"`]\\\\s*(?:OR|AND)\\\\s+[\'\\"`\\\\d]|\\\\bUNION\\\\b\\\\s+(?:ALL\\\\s+)?\\\\bSELECT\\\\b\\\\s+(?:[0-9]|NULL\\\\b|@@|0x|CONCAT|CHAR)|\\\\bSLEEP\\\\s*[(]|\\\\bBENCHMARK\\\\s*[(]|\\\\bEXTRACTVALUE\\\\s*[(]|\\\\bUPDATEXML\\\\s*[(]|/[*][!*]|;\\\\s*(?:DROP|ALTER|CREATE|TRUNCATE)\\\\b)~"}], "cve": "CVE-2022-33965", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2022-33965", "description": "WP Visitor Statistics <=5.7 unauthenticated SQL injection via refUrlDetails AJAX action", "method": "POST", "mode": "block", "severity": 9.8, "slug": "wp-stats-manager", "tags": ["sql-injection", "unauthenticated", "ajax"], "target": "plugin", "versions": "<=5.7"}, "RULE-CVE-2022-33965-07": {"ajax_action": "uoSummary", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?i)(?:[\'\\"`]\\\\s*(?:OR|AND)\\\\s+[\'\\"`\\\\d]|\\\\bUNION\\\\b\\\\s+(?:ALL\\\\s+)?\\\\bSELECT\\\\b\\\\s+(?:[0-9]|NULL\\\\b|@@|0x|CONCAT|CHAR)|\\\\bSLEEP\\\\s*[(]|\\\\bBENCHMARK\\\\s*[(]|\\\\bEXTRACTVALUE\\\\s*[(]|\\\\bUPDATEXML\\\\s*[(]|/[*][!*]|;\\\\s*(?:DROP|ALTER|CREATE|TRUNCATE)\\\\b)~"}], "cve": "CVE-2022-33965", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2022-33965", "description": "WP Visitor Statistics <=5.7 unauthenticated SQL injection via uoSummary AJAX action", "method": "POST", "mode": "block", "severity": 9.8, "slug": "wp-stats-manager", "tags": ["sql-injection", "unauthenticated", "ajax"], "target": "plugin", "versions": "<=5.7"}, "RULE-CVE-2022-33965-08": {"ajax_action": "deleteIpAddress", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?i)(?:[\'\\"`]\\\\s*(?:OR|AND)\\\\s+[\'\\"`\\\\d]|\\\\bUNION\\\\b\\\\s+(?:ALL\\\\s+)?\\\\bSELECT\\\\b\\\\s+(?:[0-9]|NULL\\\\b|@@|0x|CONCAT|CHAR)|\\\\bSLEEP\\\\s*[(]|\\\\bBENCHMARK\\\\s*[(]|\\\\bEXTRACTVALUE\\\\s*[(]|\\\\bUPDATEXML\\\\s*[(]|/[*][!*]|;\\\\s*(?:DROP|ALTER|CREATE|TRUNCATE)\\\\b)~"}], "cve": "CVE-2022-33965", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2022-33965", "description": "WP Visitor Statistics <=5.7 unauthenticated SQL injection via deleteIpAddress AJAX action", "method": "POST", "mode": "block", "severity": 9.8, "slug": "wp-stats-manager", "tags": ["sql-injection", "unauthenticated", "ajax"], "target": "plugin", "versions": "<=5.7"}, "RULE-CVE-2022-33965-09": {"ajax_action": "updateIpAddress", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?i)(?:[\'\\"`]\\\\s*(?:OR|AND)\\\\s+[\'\\"`\\\\d]|\\\\bUNION\\\\b\\\\s+(?:ALL\\\\s+)?\\\\bSELECT\\\\b\\\\s+(?:[0-9]|NULL\\\\b|@@|0x|CONCAT|CHAR)|\\\\bSLEEP\\\\s*[(]|\\\\bBENCHMARK\\\\s*[(]|\\\\bEXTRACTVALUE\\\\s*[(]|\\\\bUPDATEXML\\\\s*[(]|/[*][!*]|;\\\\s*(?:DROP|ALTER|CREATE|TRUNCATE)\\\\b)~"}], "cve": "CVE-2022-33965", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2022-33965", "description": "WP Visitor Statistics <=5.7 unauthenticated SQL injection via updateIpAddress AJAX action", "method": "POST", "mode": "block", "severity": 9.8, "slug": "wp-stats-manager", "tags": ["sql-injection", "unauthenticated", "ajax"], "target": "plugin", "versions": "<=5.7"}, "RULE-CVE-2022-33965-10": {"ajax_action": "save_ipadress", "conditions": [{"name": "ARGS", "type": "regex", "value": "~(?i)(?:[\'\\"`]\\\\s*(?:OR|AND)\\\\s+[\'\\"`\\\\d]|\\\\bUNION\\\\b\\\\s+(?:ALL\\\\s+)?\\\\bSELECT\\\\b\\\\s+(?:[0-9]|NULL\\\\b|@@|0x|CONCAT|CHAR)|\\\\bSLEEP\\\\s*[(]|\\\\bBENCHMARK\\\\s*[(]|\\\\bEXTRACTVALUE\\\\s*[(]|\\\\bUPDATEXML\\\\s*[(]|/[*][!*]|;\\\\s*(?:DROP|ALTER|CREATE|TRUNCATE)\\\\b)~"}], "cve": "CVE-2022-33965", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2022-33965", "description": "WP Visitor Statistics <=5.7 unauthenticated SQL injection via save_ipadress AJAX action", "method": "POST", "mode": "block", "severity": 9.8, "slug": "wp-stats-manager", "tags": ["sql-injection", "unauthenticated", "ajax"], "target": "plugin", "versions": "<=5.7"}, "RULE-CVE-2022-3805-02": {"ajax_action": "jkit_create_element", "conditions": [{"type": "missing_capability", "value": "edit_theme_options"}], "cve": "CVE-2022-3805", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2022-3805", "description": "Jeg Elementor Kit <=2.5.6 unauthorized element creation via jkit_create_element AJAX handler", "mode": "block", "severity": 7.5, "slug": "jeg-elementor-kit", "tags": ["missing-authorization", "privilege-escalation"], "target": "plugin", "versions": "<=2.5.6"}, "RULE-CVE-2022-4059-01": {"ajax_action": "mcwp_table", "conditions": [{"name": "ARGS:id", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*[!+]|(?:--|#)\\\\s|\\\\b(?:OR|AND)\\\\s+[\'\\"]?\\\\d+[\'\\"]?\\\\s*=\\\\s*[\'\\"]?\\\\d+|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|EXTRACTVALUE\\\\s*\\\\(|UPDATEXML\\\\s*\\\\(|LOAD_FILE\\\\s*\\\\()~i"}], "cve": "CVE-2022-4059", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2022-4059", "description": "Cryptocurrency Widgets Pack <2.0 unauthenticated SQL injection via mcwp_table AJAX action", "mode": "block", "severity": 9.8, "slug": "cryptocurrency-widgets-pack", "tags": ["sql-injection", "unauthenticated"], "target": "plugin", "versions": "<2.0"}, "RULE-CVE-2022-41786-01": {"ajax_action": "wpjobportal_ajax", "conditions": [{"name": "ARGS:task", "type": "exists"}, {"name": "ARGS:task", "type": "regex", "value": "~^(deletecompanylogo|deleteUserPhoto|deleteResumeLogo|removeResumeFileById|deleteResumeSectionAjax)$~i"}], "cve": "CVE-2022-41786", "method": "POST", "mode": "block", "severity": 9.8, "slug": "wp-job-portal", "target": "plugin", "versions": "<=2.0.1"}, "RULE-CVE-2022-42699-01": {"ajax_action": "swpsmtp_clear_log", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2022-42699", "description": "Easy WP SMTP <=1.5.1 missing authorization on swpsmtp_clear_log allows subscriber+ log file deletion", "mode": "block", "severity": 9.1, "slug": "easy-wp-smtp", "target": "plugin", "versions": "<=1.5.1"}, "RULE-CVE-2022-42699-02": {"ajax_action": "swpsmtp_self_destruct", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2022-42699", "description": "Easy WP SMTP <=1.5.1 missing authorization on swpsmtp_self_destruct allows subscriber+ plugin deletion", "mode": "block", "severity": 9.1, "slug": "easy-wp-smtp", "target": "plugin", "versions": "<=1.5.1"}, "RULE-CVE-2022-4290-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/edit-tags\\\\.php(?:\\\\?|$)~"}, {"name": "ARGS:tag-name", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|\\\\b(?:SLEEP|BENCHMARK)\\\\s*\\\\(|\\\\binformation_schema\\\\b|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|--\\\\s|0x[0-9a-fA-F]{4,})~i"}], "cve": "CVE-2022-4290", "description": "Cyr to Lat <=3.5 authenticated SQL injection via tag/term name in ctl_sanitize_title (edit-tags.php)", "mode": "block", "severity": 8.8, "slug": "cyr3lat", "target": "plugin", "versions": "<=3.5"}, "RULE-CVE-2022-4290-02": {"ajax_action": "add-tag", "conditions": [{"name": "ARGS:tag-name", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\s|/\\\\*.*\\\\*/|\\\\b(?:SLEEP|BENCHMARK)\\\\s*\\\\(|\\\\binformation_schema\\\\b|\\\\b(?:OR|AND)\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+|--\\\\s|0x[0-9a-fA-F]{4,})~i"}], "cve": "CVE-2022-4290", "description": "Cyr to Lat <=3.5 authenticated SQL injection via add-tag AJAX tag-name", "mode": "block", "severity": 8.8, "slug": "cyr3lat", "target": "plugin", "versions": "<=3.5"}, "RULE-CVE-2022-4328-01": {"ajax_action": "cfom_upload_file", "conditions": [{"name": "ARGS:name", "type": "regex", "value": "~\\\\.(?:ph(?:p[0-9]?|s|tml?|t|ar)|s?html?|cgi|asp|aspx|jsp|jspx|cfm|user\\\\.ini)$|[\\\\\\\\/]\\\\.htaccess$|[\\\\\\\\/]\\\\.htpasswd$|\\\\0~i"}], "cve": "CVE-2022-4328", "description": "N-Media WooCommerce Checkout Fields <=17.3 unauthenticated arbitrary file upload via cfom_upload_file AJAX handler", "mode": "block", "slug": "n-media-woocommerce-checkout-fields", "target": "plugin", "versions": "<=17.3"}, "RULE-CVE-2022-43453-01": {"ajax_action": "wptools_get_ajax_data", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2022-43453", "mode": "block", "severity": 8.8, "slug": "wptools", "target": "plugin", "versions": "<3.43"}, "RULE-CVE-2022-43453-03": {"ajax_action": "wptools_get_speed_info", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2022-43453", "mode": "block", "severity": 8.8, "slug": "wptools", "target": "plugin", "versions": "<3.43"}, "RULE-CVE-2022-43453-04": {"ajax_action": "wptools_dismissible_notice", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2022-43453", "mode": "block", "severity": 8.8, "slug": "wptools", "target": "plugin", "versions": "<3.43"}, "RULE-CVE-2022-43453-05": {"ajax_action": "wptools_dismissible_notice2", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2022-43453", "mode": "block", "severity": 8.8, "slug": "wptools", "target": "plugin", "versions": "<3.43"}, "RULE-CVE-2022-43453-06": {"ajax_action": "wptools_bill_go_pro_hide", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2022-43453", "mode": "block", "severity": 8.8, "slug": "wptools", "target": "plugin", "versions": "<3.43"}, "RULE-CVE-2022-4501-01": {"ajax_action": "vc_save_data", "conditions": [{"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2022-4501", "description": "Mega Addons For WPBakery Page Builder <=4.3.0 missing authorization on vc_save_data AJAX action allows subscriber+ to overwrite plugin settings", "mode": "block", "severity": 6.5, "slug": "mega-addons-for-visual-composer", "target": "plugin", "versions": "<=4.3.0"}, "RULE-CVE-2022-45354-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:/wp-json/download-monitor/v1/(?:download_reports|user_reports|user_data))(?:/|\\\\?|$)~i"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2022-45354", "method": "GET", "mode": "block", "severity": 7.5, "slug": "download-monitor", "target": "plugin", "versions": "<=4.7.60"}, "RULE-CVE-2022-45354-02": {"action": "init", "conditions": [{"name": "ARGS:rest_route", "type": "regex", "value": "~^/download-monitor/v1/(?:download_reports|user_reports|user_data)(?:/|$)~i"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2022-45354", "method": "GET", "mode": "block", "severity": 7.5, "slug": "download-monitor", "target": "plugin", "versions": "<=4.7.60"}, "RULE-CVE-2022-45830-01": {"action": "admin_init", "conditions": [{"name": "ARGS:wp_analytify_log_out", "type": "exists"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2022-45830", "method": "POST", "mode": "block", "severity": 9.8, "slug": "wp-analytify", "target": "plugin", "versions": "<=4.2.3"}, "RULE-CVE-2022-47615-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/lp/v1/courses/archive-course(?:/|\\\\?|$)~"}, {"name": "ARGS:template_path", "type": "regex", "value": "~(?:(?:\\\\.\\\\.[\\\\\\\\/]){2,}|(?:wp-config\\\\.php|/etc/passwd|\\\\.htaccess|\\\\.env|debug\\\\.log|error_log|proc/self))~i"}], "cve": "CVE-2022-47615", "description": "LearnPress <=4.1.7.3.2 unauthenticated LFI via template_path parameter in REST API", "mode": "block", "severity": 9.8, "slug": "learnpress", "target": "plugin", "versions": "<=4.1.7.3.2"}, "RULE-CVE-2022-47615-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/lp/v1/courses/archive-course(?:/|\\\\?|$)~"}, {"name": "ARGS:template_path_item", "type": "regex", "value": "~(?:(?:\\\\.\\\\.[\\\\\\\\/]){2,}|(?:wp-config\\\\.php|/etc/passwd|\\\\.htaccess|\\\\.env|debug\\\\.log|error_log|proc/self))~i"}], "cve": "CVE-2022-47615", "description": "LearnPress <=4.1.7.3.2 unauthenticated LFI via template_path_item parameter in REST API", "mode": "block", "severity": 9.8, "slug": "learnpress", "target": "plugin", "versions": "<=4.1.7.3.2"}, "RULE-CVE-2022-47615-03": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/lp/v1/courses/archive-course(?:/|\\\\?|$)~"}, {"name": "ARGS:template_pagination_path", "type": "regex", "value": "~(?:(?:\\\\.\\\\.[\\\\\\\\/]){2,}|(?:wp-config\\\\.php|/etc/passwd|\\\\.htaccess|\\\\.env|debug\\\\.log|error_log|proc/self))~i"}], "cve": "CVE-2022-47615", "description": "LearnPress <=4.1.7.3.2 unauthenticated LFI via template_pagination_path parameter in REST API", "mode": "block", "severity": 9.8, "slug": "learnpress", "target": "plugin", "versions": "<=4.1.7.3.2"}, "RULE-CVE-2022-4972-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|[?&])rest_route=)/download-monitor/v1/download_reports(?:[/?&]|$)~"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2022-4972", "method": "GET", "mode": "block", "severity": 7.5, "slug": "download-monitor", "target": "plugin", "versions": "<=4.7.51"}, "RULE-CVE-2022-4972-02": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|[?&])rest_route=)/download-monitor/v1/download_reports(?:[/?&]|$)~"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2022-4972", "method": "POST", "mode": "block", "severity": 7.5, "slug": "download-monitor", "target": "plugin", "versions": "<=4.7.51"}, "RULE-CVE-2022-4972-03": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|[?&])rest_route=)/download-monitor/v1/user_reports(?:[/?&]|$)~"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2022-4972", "method": "GET", "mode": "block", "severity": 7.5, "slug": "download-monitor", "target": "plugin", "versions": "<=4.7.51"}, "RULE-CVE-2022-4972-04": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|[?&])rest_route=)/download-monitor/v1/user_reports(?:[/?&]|$)~"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2022-4972", "method": "POST", "mode": "block", "severity": 7.5, "slug": "download-monitor", "target": "plugin", "versions": "<=4.7.51"}, "RULE-CVE-2022-4972-05": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|[?&])rest_route=)/download-monitor/v1/user_data(?:[/?&]|$)~"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2022-4972", "method": "GET", "mode": "block", "severity": 7.5, "slug": "download-monitor", "target": "plugin", "versions": "<=4.7.51"}, "RULE-CVE-2022-4972-06": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|[?&])rest_route=)/download-monitor/v1/user_data(?:[/?&]|$)~"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2022-4972", "method": "POST", "mode": "block", "severity": 7.5, "slug": "download-monitor", "target": "plugin", "versions": "<=4.7.51"}, "RULE-CVE-2022-4972-07": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|[?&])rest_route=)/download-monitor/v1/templates(?:[/?&]|$)~"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2022-4972", "method": "GET", "mode": "block", "severity": 7.5, "slug": "download-monitor", "target": "plugin", "versions": "<=4.7.51"}, "RULE-CVE-2022-4972-08": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|[?&])rest_route=)/download-monitor/v1/templates(?:[/?&]|$)~"}, {"type": "missing_capability", "value": "manage_options"}], "cve": "CVE-2022-4972", "method": "POST", "mode": "block", "severity": 7.5, "slug": "download-monitor", "target": "plugin", "versions": "<=4.7.51"}, "RULE-CVE-2023-0084-02": {"ajax_action": "mf_admin_action", "conditions": [{"name": "ARGS:form_data", "type": "regex", "value": "~(?:]|on(?:error|load|mouseover|click|focus|blur)\\\\s*=|javascript\\\\s*:|svg\\\\s+onload=)~i"}], "cve": "CVE-2023-0084", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2023-0084", "description": "MetForm <=3.1.2 stored XSS via admin submissions list view", "mode": "block", "severity": 6.1, "slug": "metform", "tags": ["xss", "stored"], "target": "plugin", "versions": "<=3.1.2"}, "RULE-CVE-2023-0579-01": {"ajax_action": "yarpp_display", "conditions": [{"name": "ARGS:ID", "type": "regex", "value": "~(?:UNION(?:/\\\\*.*?\\\\*/|\\\\s)+(?:ALL(?:/\\\\*.*?\\\\*/|\\\\s)+)?SELECT\\\\b|/\\\\*.*?\\\\*/|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\b|\\\\b(?:OR|AND)\\\\b(?:/\\\\*.*?\\\\*/|\\\\s)+[0-9]+\\\\s*=\\\\s*[0-9]+|(?:--|#)(?:\\\\s|$)|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|WAITFOR(?:/\\\\*.*?\\\\*/|\\\\s)+DELAY)~i"}], "cve": "CVE-2023-0579", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2023-0579", "description": "YARPP <=5.30.2 authenticated SQL injection via yarpp_display AJAX handler ID parameter", "mode": "block", "severity": 8.8, "slug": "yet-another-related-posts-plugin", "tags": ["sql-injection", "authenticated", "ajax"], "target": "plugin", "versions": "<=5.30.2"}, "RULE-CVE-2023-0579-02": {"ajax_action": "yarpp_display_preview", "conditions": [{"name": "ARGS:ID", "type": "regex", "value": "~(?:UNION(?:/\\\\*.*?\\\\*/|\\\\s)+(?:ALL(?:/\\\\*.*?\\\\*/|\\\\s)+)?SELECT\\\\b|/\\\\*.*?\\\\*/|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE)\\\\b|\\\\b(?:OR|AND)\\\\b(?:/\\\\*.*?\\\\*/|\\\\s)+[0-9]+\\\\s*=\\\\s*[0-9]+|(?:--|#)(?:\\\\s|$)|SLEEP\\\\s*\\\\(|BENCHMARK\\\\s*\\\\(|WAITFOR(?:/\\\\*.*?\\\\*/|\\\\s)+DELAY)~i"}], "cve": "CVE-2023-0579", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2023-0579", "description": "YARPP <=5.30.2 authenticated SQL injection via yarpp_display_preview AJAX handler ID parameter", "mode": "block", "severity": 8.8, "slug": "yet-another-related-posts-plugin", "tags": ["sql-injection", "authenticated", "ajax"], "target": "plugin", "versions": "<=5.30.2"}, "RULE-CVE-2023-0600-01": {"ajax_action": "getContentUrlDayView", "conditions": [{"name": "ARGS:countryName", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE|CREATE)\\\\s|/[*].*[*]/|(?:--|#)\\\\s|\\\\bOR\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+)~i"}, {"name": "ARGS:currentPage", "type": "regex", "value": "~(?:UNION|SELECT|;|DROP|DELETE|INSERT|CREATE|ALTER)~i"}, {"name": "ARGS:itemsPerPage", "type": "regex", "value": "~(?:UNION|SELECT|;|DROP|DELETE|INSERT|CREATE|ALTER)~i"}], "cve": "CVE-2023-0600", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2023-0600", "description": "WP Stats Manager <=6.8.1 authenticated SQL injection via getContentUrlDayView AJAX handler", "mode": "block", "severity": 9.8, "slug": "wp-stats-manager", "tags": ["sql-injection", "authenticated"], "target": "plugin", "versions": "<=6.8.1"}, "RULE-CVE-2023-0600-02": {"ajax_action": "getDateWiseLocationDetail", "conditions": [{"name": "ARGS:id", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE|CREATE)\\\\s|/[*].*[*]/|(?:--|#)\\\\s|\\\\bOR\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+)~i"}, {"name": "ARGS:countryName", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE|CREATE)\\\\s|/[*].*[*]/|(?:--|#)\\\\s|\\\\bOR\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+)~i"}, {"name": "ARGS:orderby", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE|CREATE)\\\\s|/[*].*[*]/|(?:--|#)\\\\s)~i"}, {"name": "ARGS:currentPage", "type": "regex", "value": "~(?:UNION|SELECT|;|DROP|DELETE|INSERT|CREATE|ALTER)~i"}, {"name": "ARGS:itemsPerPage", "type": "regex", "value": "~(?:UNION|SELECT|;|DROP|DELETE|INSERT|CREATE|ALTER)~i"}], "cve": "CVE-2023-0600", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2023-0600", "description": "WP Stats Manager <=6.8.1 authenticated SQL injection via getDateWiseLocationDetail AJAX handler", "mode": "block", "severity": 9.8, "slug": "wp-stats-manager", "tags": ["sql-injection", "authenticated"], "target": "plugin", "versions": "<=6.8.1"}, "RULE-CVE-2023-0600-03": {"ajax_action": "liveStats", "conditions": [{"name": "ARGS:id", "type": "regex", "value": "~(?:UNION\\\\s+(?:ALL\\\\s+)?SELECT\\\\s|;\\\\s*(?:DROP|DELETE|INSERT|UPDATE|CREATE)\\\\s|/[*].*[*]/|(?:--|#)\\\\s|\\\\bOR\\\\s+\\\\d+\\\\s*=\\\\s*\\\\d+)~i"}], "cve": "CVE-2023-0600", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2023-0600", "description": "WP Stats Manager <=6.8.1 authenticated SQL injection via liveStats AJAX handler", "mode": "block", "severity": 9.8, "slug": "wp-stats-manager", "tags": ["sql-injection", "authenticated"], "target": "plugin", "versions": "<=6.8.1"}, "RULE-CVE-2023-0714-01": {"action": "rest_api_init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~(?:^/wp-json|(?:^|&|\\\\?)rest_route=)/metform/v1/submit(?:[/?]|$)~"}, {"name": "FILES:file_attachment:name", "type": "regex", "value": "~\\\\.(?:php[0-9]?|phtml|pht|phar|t?html?|shtml?| asp|aspx|jspx?|cgi|pl|py|sh|exe|dll|bat|cmd|vbs|ps1|reg|ini|htaccess|htpasswd|user\\\\.ini)$~i"}], "cve": "CVE-2023-0714", "cve_link": "https://nvd.nist.gov/vuln/detail/CVE-2023-0714", "description": "Metform <=3.2.4 unauthenticated arbitrary file upload via REST API submit endpoint", "method": "POST", "mode": "block", "severity": 9.8, "slug": "metform", "tags": ["arbitrary-file-upload", "unauthenticated", "rest-api", "cwe-434"], "target": "plugin", "versions": "<=3.2.4"}, "RULE-CVE-2023-2023-01": {"action": "init", "conditions": [{"name": "REQUEST_URI", "type": "regex", "value": "~^/wp-admin/admin\\\\.php~"}, {"name": "ARGS:page", "type": "equals", "value": "custom-404-pro-logs"}, {"name": "ARGS:s", "type": "regex", "value": "~(?:]|on(?:error|load|focus|mouseover|click|keyup|keydown|submit)\\\\s*=|javascript\\\\s*:|