Impact
WordPress Plugin Survey & Poll version 1.5.7.3 exposes an SQL injection flaw that allows an attacker to inject arbitrary SQL code through the wp_sap cookie. The vulnerability can be used by unauthenticated users to retrieve sensitive database content such as usernames, passwords, and other confidential data. The core weakness (CWE-89) indicates insufficient input sanitization of cookie data, enabling attackers to compromise the integrity and confidentiality of the WordPress database.
Affected Systems
WordPress sites that have installed the Modalsurvey Survey & Poll plugin up to and including version 1.5.7.3 are affected. Sites running newer releases are presumed not to be vulnerable; earlier or unreleased versions lack detailed information, so caution is advised if the plugin is used.
Risk and Exploitability
The CVSS score of 8.8 classifies this flaw as High severity. Although the EPSS score is not available, the publicly documented exploitation references indicate that the vulnerability is feasible for remote attackers acting without prior authentication. The keystone "wp_sap" cookie can be manipulated freely, making the attack path straightforward for an attacker with internet access to the site. As the CVE is not listed in the CISA KEV catalog, no known widespread exploits are recorded as of the latest data.
OpenCVE Enrichment