Impact
The vulnerability is a classic SQL injection flaw that allows an unauthenticated attacker to inject arbitrary SQL statements via the albid parameter of the Apptha Slider Gallery plugin. By sending malicious GET requests containing crafted SQL payloads, an attacker can read or manipulate database contents. The impact includes full compromise of stored user credentials and authentication hashes, potentially leading to account takeover or further application compromise.
Affected Systems
The affected product is the Apptha Slider Gallery WordPress plugin version 1.0. No other versions or vendors are listed as affected. The plugin is deployed on WordPress sites that have not applied any updates beyond the original release.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. There is no EPSS score available, so the precise likelihood of exploitation cannot be quantified, but the lack of authentication barrier makes exploitation trivial for any unauthenticated user. The vulnerability is not listed in CISA’s KEV catalog. The attacker’s attack vector is inferred to be remote via HTTP requests to the site hosting the plugin, as the mitigation requires no elevated privileges or local access.
OpenCVE Enrichment