Executive brief
The Answer My Question plugin for WordPress, which allows users to manage questions and answers, contains a security flaw that allows unauthorized individuals to access the website's database. By sending a specially crafted request, an attacker can steal sensitive information such as site configuration data and user-related terms. This could lead to a significant data breach or help an attacker gain further control over the website.
Technical details
An SQL injection vulnerability exists in the Answer My Question plugin (version 1.3) for WordPress due to improper sanitization of the 'id' POST parameter in the modal.php file. The root cause is that the $_POST['id'] variable is not escaped before being used in a database query. An unauthenticated remote attacker can exploit this by sending a crafted POST request containing UNION-based SQL statements to the modal.php endpoint. Successful exploitation allows the attacker to execute arbitrary SQL queries and extract sensitive information from the WordPress database, such as terms and configuration data. The plugin has been closed on the WordPress repository since 2012 and no official patch is available.
Affected products
- mattkaye Answer My Question 1.3
Timeline
- 2012-10-07: other: Plugin closed on WordPress.org repository
- 2016-11-17: disclosed: Exploit published on Exploit-DB
- 2026-06-15: advisory: CVE published/updated in NVD dataset