WPvivid exposed its staging workflow to unauthenticated requests and used the attacker-controlled table prefix in database statements, while BitFire blocks automated exploit requests, detects SQL injection, and protects sensitive database outcomes.
Affected sites
900,000+
Attack class
SQL Injection
BitFire protectionProtected by BitFire Bot Protection + WAF
Ultimate Member lets an unauthenticated visitor inject SQL through its member-directory sorting parameter, while BitFire WAF inspects that input and rejects SQL keywords and evasion signatures before the plugin builds the query.