Impact
The TARIFFUXX WordPress plugin is vulnerable to SQL Injection in versions 1.4 and earlier due to insufficient neutralization of user–supplied input. The flaw allows an authenticated user with Contributor-level or higher access to inject malicious SQL via the id attribute of the tariffuxx_configurator shortcode, potentially enabling unauthorized extraction of data from the database and compromising confidentiality.
Affected Systems
The vulnerability affects the TARIFFUXX plugin for WordPress. All installed versions up to and including 1.4 are susceptible; no other WordPress core components are impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity. The EPSS score of less than 1% suggests a very low exploitation probability at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires authenticated access, so an attacker must possess Contributor or higher credentials, typically by inserting a crafted id value into the shortcode within the WordPress administration interface. Once authenticated, the attacker could extract sensitive database content.
OpenCVE Enrichment