Synopsis
A regression was introduced in version 4.0.0 of WP Post Author, the multi-authors module stores the co-author list in the wpma_author post meta and later interpolates each stored value directly into a SQL query. Neither end of that path is safe.
On write, awpa_ma_save_metabox() takes $_POST['wpma_metabox_authors_list'], splits it on commas, and stores each element verbatim. The handler computes a sanitized copy and then stores the raw value instead:
// includes/multi-authors/wpa-multi-authors.php:113
foreach ($data as $key => $user_id) {
$userid = sanitize_text_field($user_id); // computed and never used
add_post_meta($post_id, 'wpma_author', $user_id); // raw value storedThe handler has no nonce verification, no current_user_can('edit_post', $post_id) check, and no autosave guard, even though the metabox still emits a nonce field at line 91 that nothing ever validates.
On read, awpa_ma_get_guest_author() concatenates the stored value into the query with no prepare() and no cast:
// includes/multi-authors/wpa-multi-authors.php:299
public function awpa_ma_get_guest_author($guest_id)
{
global $wpdb;
$table_name = $wpdb->prefix . "wpa_guest_authors";
$query = "SELECT id, user_email, display_name, user_nicename FROM $table_name where id = $guest_id";
$guest_author = $wpdb->get_results($query, OBJECT);
return $guest_author ? $guest_author[0] : false;
}Three of the returned columns are echoed back into the page as data-nice_name, data-user_email and data-display_name attributes, so a UNION SELECT returns the attacker's chosen data directly in the HTML response.
Solution
Upgrade to the WordPress Plugin WP Post Author version 4.1.0 or later.
Disclosure Timeline
All information within TRA advisories is provided “as is”, without warranty of any kind, including the implied warranties of merchantability and fitness for a particular purpose, and with no guarantee of completeness, accuracy, or timeliness. Individuals and organizations are responsible for assessing the impact of any actual or potential security vulnerability.
Tenable takes product security very seriously. If you believe you have found a vulnerability in one of our products, we ask that you please work with us to quickly resolve it in order to protect customers. Tenable believes in responding quickly to such reports, maintaining communication with researchers, and providing a solution in short order.
For more details on submitting vulnerability information, please see our Vulnerability Reporting Guidelines page.
If you have questions or corrections about this advisory, please email [email protected]
Tenable One
Request a demo
The world’s leading AI-powered exposure management platform.
Thank You
Thank you for your interest in Tenable One.
A representative will be in touch soon.
Form ID: 7469
Form Name: one-eval
Form Class: c-form form-panel__global-form c-form--mkto js-mkto-no-css js-form-hanging-label c-form--hide-comments
Form Wrapper ID: one-eval-form-wrapper
Confirmation Class: one-eval-confirmform-modal
Simulate Success