Impact
The WordPress Filter & Grids plugin is vulnerable to SQL injection through the 'phrase' parameter, enabling unauthenticated attackers to append malicious queries and retrieve sensitive database contents. This flaw is a classic injection weakness (CWE‑89) and is limited to MariaDB, as the query produces a syntax error on MySQL.
Affected Systems
Up to and including version 3.2.0 of the YMC Filter (Filter & Grids) plugin for WordPress is affected. All installations of this plugin that have not been updated past 3.2.0 expose the vulnerable code.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, while an EPSS score of less than 1% suggests low exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it via unauthenticated access to the plugin’s search functionality, provided the site uses MariaDB.
OpenCVE Enrichment