Impact
The Payamito SMS WooCommerce plugin for WordPress contains an unauthenticated time-based blind SQL injection flaw in the 'columns' parameter across all releases up to and including 1.3.5. Insufficient escaping and lack of prepared statements allow an attacker to inject arbitrary SQL through this parameter. This vulnerability is identified as CWE-89 and can be leveraged to extract sensitive data from the underlying database without requiring authentication, potentially exposing customer information and site credentials.
Affected Systems
WordPress installations using the Payamito SMS WooCommerce plugin version 1.3.5 or earlier are affected. The flaw exists in the core admin and database handling classes of the plugin and has no direct dependency on other plugins.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely by issuing crafted requests to the plugin’s front‑end or admin endpoint containing the malicious 'columns' value, thereby inducing measurable delays that reveal boolean or numeric results. Such an attack path does not require prior authentication and can be automated with standard SQL injection tools.
OpenCVE Enrichment