WordPress - Post Author Second Order SQLi

Medium

Synopsis

A regression was introduced in version 4.0.0 of WP Post Author, the multi-authors module stores the co-author list in the wpma_author post meta and later interpolates each stored value directly into a SQL query. Neither end of that path is safe.

On write, awpa_ma_save_metabox() takes $_POST['wpma_metabox_authors_list'], splits it on commas, and stores each element verbatim. The handler computes a sanitized copy and then stores the raw value instead:

// includes/multi-authors/wpa-multi-authors.php:113
foreach ($data as $key => $user_id) {
   $userid = sanitize_text_field($user_id);        // computed and never used
   add_post_meta($post_id, 'wpma_author', $user_id); // raw value stored

The handler has no nonce verification, no current_user_can('edit_post', $post_id) check, and no autosave guard, even though the metabox still emits a nonce field at line 91 that nothing ever validates.

On read, awpa_ma_get_guest_author() concatenates the stored value into the query with no prepare() and no cast:

// includes/multi-authors/wpa-multi-authors.php:299
public function awpa_ma_get_guest_author($guest_id)
{
   global $wpdb;
   $table_name = $wpdb->prefix . "wpa_guest_authors";
   $query = "SELECT id, user_email, display_name, user_nicename FROM $table_name where id = $guest_id";
   $guest_author = $wpdb->get_results($query, OBJECT);
   return $guest_author ? $guest_author[0] : false;
}

Three of the returned columns are echoed back into the page as data-nice_name, data-user_email and data-display_name attributes, so a UNION SELECT returns the attacker's chosen data directly in the HTML response.

Solution

Upgrade to the WordPress Plugin WP Post Author version 4.1.0 or later.

Disclosure Timeline

October 05 2026 - Vulnerability reported to the vendor
October 08 2026 - The vendor has released version 4.1.0 and is requesting a retest.
October 08 2026 - Tenable confirm the fix
October 09 2026 - The vendor has released version 4.1.1 and is requesting a retest.
October 09 2026 - Tenable confirm that the fix is ​​still okay

All information within TRA advisories is provided “as is”, without warranty of any kind, including the implied warranties of merchantability and fitness for a particular purpose, and with no guarantee of completeness, accuracy, or timeliness. Individuals and organizations are responsible for assessing the impact of any actual or potential security vulnerability.

Tenable takes product security very seriously. If you believe you have found a vulnerability in one of our products, we ask that you please work with us to quickly resolve it in order to protect customers. Tenable believes in responding quickly to such reports, maintaining communication with researchers, and providing a solution in short order.

For more details on submitting vulnerability information, please see our Vulnerability Reporting Guidelines page.

If you have questions or corrections about this advisory, please email [email protected]