Impact
The Easy Email Subscription WordPress plugin contains a SQL injection flaw that is triggered through the 'uid' parameter. Because the plugin does not properly escape user-supplied input and fails to prepare the underlying SQL query, an attacker who can authenticate as an administrator can embed additional SQL statements. This vulnerability allows the execution of arbitrary queries against the database and the retrieval of sensitive data, undermining the confidentiality of the WordPress site's contents and the information stored in the associated database.
Affected Systems
The issue affects all installations of the yudiz Easy Email Subscription plugin version 1.3 and earlier. Any WordPress site that has this plugin activated and possesses a user account with Administrator or higher privileges is susceptible to exploitation.
Risk and Exploitability
The CVSS score of 4.9 indicates a moderate severity risk, while the EPSS score of less than 1% suggests that the likelihood of exploitation in the wild remains low. The vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires a legitimate administrator account and is therefore confined to authenticated users; an attacker must first gain elevated WordPress credentials before leveraging the flaw to extract data.
OpenCVE Enrichment