Impact
The Shipping Rate By Cities plugin for WordPress is vulnerable to SQL injection through the 'city' parameter due to insufficient escaping and lack of prepared statements. This flaw allows unauthenticated attackers to append malicious SQL to existing queries, enabling them to read sensitive database content. The weakness is classified as CWE‑89 and has a CVSS score of 7.5.
Affected Systems
The vulnerability affects all releases of the Trident Technolabs Shipping Rate By Cities WordPress plugin up to and including version 2.0.0. Sites using any of these versions are potentially exposed.
Risk and Exploitability
The CVSS rating indicates moderate‑to‑high risk while the EPSS score of less than 1% suggests low current exploitation likelihood. The plugin can be targeted via HTTP requests that supply a crafted 'city' value; authentication is not required. Attackers could extract confidential data, compromising database confidentiality. No change to the KEV catalog has been recorded for this issue.
OpenCVE Enrichment