Impact
The ProjectList WordPress plugin includes a time‑based SQL injection flaw in the 'id' parameter across all releases up to and including 0.3.0. An authenticated user with Editor privileges could manipulate this parameter to append arbitrary SQL statements to the existing query, allowing the extraction of sensitive database contents. The weakness is a classic injection failure (CWE‑89) and does not grant remote code execution, but it can compromise confidential data stored in the WordPress database.
Affected Systems
The affected plugin is ProjectList, developed by vendor ov3rkll for WordPress. All versions numbered 0.3.0 or earlier are susceptible; newer releases are assumed to have addressed the issue.
Risk and Exploitability
The CVSS score of 4.9 positions the flaw at moderate severity, and the EPSS score of less than 1% indicates a low probability of exploitation under current conditions. Since the vulnerability requires a user to be logged in with Editor or higher privileges, its operational impact is limited to sites where such accounts exist, and it is not listed in the CISA KEV catalog.
OpenCVE Enrichment