Impact
Single Personal Message 1.0.3 contains a SQL injection flaw that lets an authenticated attacker inject arbitrary SQL through the message parameter. The vulnerability allows the attacker to extract sensitive database content, including user credentials and site configuration, thereby compromising confidentiality and potentially enabling further escalation.
Affected Systems
The flaw affects the Single Personal Message plugin for WordPress version 1.0.3. Only installations that have this specific version installed are vulnerable; newer releases of the plugin are not affected according to the available data.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. Because the vulnerability requires authenticated access, the attacker must first obtain valid credentials to the WordPress admin interface. The EPSS score is not available, and the CVE is not listed in CISA KEV, suggesting the exploitation probability is not yet quantified. However, the presence of the flaw in a widely used plugin and the ability to read database tables creates a significant risk for sites that have not applied an update.
OpenCVE Enrichment