Impact
The Bucketlister plugin for WordPress contains an SQL Injection flaw in the shortcode attributes "category" and "id". The plugin fails to escape or prepare user‑supplied values, allowing an authenticated contributor or higher to inject additional SQL statements into existing queries. This leads to unauthorized extraction of sensitive database data.
Affected Systems
The vulnerability affects the WordPress plugin The Bucketlister by simonfairbairn. All releases up to version 0.1.5 inclusive are impacted. The attack requires a user account with Contributor‑level access or higher.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate severity. The EPSS score of less than 1% shows a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker must first be authenticated with at least Contributor privileges and then embed malicious shortcodes in content or directly exploit the plugin’s shortcode handling in a page or post. If successful, the attacker can append arbitrary SQL statements that may disclose or modify database information.
OpenCVE Enrichment