Executive brief
The PickPlugins Question Answer plugin for WordPress, which adds community discussion features to websites, contains a security flaw that allows unauthorized access to the site's database. By sending a specially crafted web request, an attacker can bypass security protections to view sensitive information stored in the database, such as user details or site configuration. This could lead to a significant data breach or compromise of the website's integrity.
Technical details
A SQL injection vulnerability exists in the PickPlugins Question Answer plugin for WordPress (versions <= 1.2.73) within the qa_user_profile_card() function. The flaw stems from the 'id' GET parameter in the user profile template being processed with wp_unslash(), which strips WordPress's default magic quotes protection. The resulting unsanitized input is then directly concatenated into a SQL query without the use of prepared statements or proper escaping. An unauthenticated remote attacker can exploit this by providing malicious SQL commands via the 'id' parameter to extract sensitive data from the database. The vulnerability is tracked as CWE-89.
Affected products
- PickPlugins PickPlugins Question Answer up to and including 1.2.73
Timeline
- 2026-07-28: disclosed
- 2026-07-28: advisory
References
- https://plugins.trac.wordpress.org/browser/question-answer/tags/1.2.73/templates/user-profile/user-profile-hook.php
- https://plugins.trac.wordpress.org/browser/question-answer/tags/1.2.73/templates/user-profile/user-profile.php
- https://plugins.trac.wordpress.org/browser/question-answer/trunk/templates/user-profile/user-profile-hook.php
- https://plugins.trac.wordpress.org/browser/question-answer/trunk/templates/user-profile/user-profile.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/178e2537-e900-4264-9b29-1bb5bac36f48?source=cve