Junglewise Threat Intelligence

CVE-2017-20245: Wow-Company Wow Viral Signups SQL injection in idsignup parameter

CVE-2017-20245 · Severity: high · CVSS 8.2 · Published 2026-06-09

Executive brief

The Wow Viral Signups plugin for WordPress, which is used to create subscription forms, contains a security flaw that allows unauthorized individuals to access the website's database. By sending a specially crafted request, an attacker can steal sensitive information such as user credentials, customer data, or site configuration details. This could lead to a full compromise of the website or the exposure of private user information.

Technical details

A SQL injection vulnerability exists in the Wow Viral Signups plugin (version 2.1 and earlier) for WordPress due to insufficient sanitization of the 'idsignup' POST parameter. An unauthenticated remote attacker can exploit this by sending a crafted request to the 'admin-ajax.php' endpoint with the 'action' set to 'mwp_signup_send'. Successful exploitation allows for boolean-based and time-based blind SQL injection, enabling the attacker to extract arbitrary data from the WordPress database. The plugin was closed on the WordPress repository in December 2016 and remains unpatched; users are advised to uninstall the software.

Affected products

  • Wow-Company Wow Viral Signups <= 2.1

Timeline

  • 2016-12-06: other: Plugin closed on WordPress.org repository
  • 2017-03-15: disclosed: Vulnerability discovered and developer informed
  • 2017-03-29: advisory: Public disclosure of advisory and exploit code
  • 2026-06-09: other: CVE record published/updated

References