Impact
An unauthenticated SQL injection flaw exists in the Capella theme for WordPress versions 2.5.5 and earlier. The vulnerability allows an attacker to construct arbitrary SQL statements that the theme executes against the site database, leading to potential data theft, data modification, or destruction of critical content. The flaw stems from improper sanitization of data passed to SQL queries, as identified by the CWE-89 classification.
Affected Systems
The issue affects the ThemeGoods Capella WordPress theme, specifically all releases up to and including 2.5.5. Any site deploying this theme is vulnerable unless later versions are used.
Risk and Exploitability
The high CVSS score of 9.3 indicates a severe risk. Because the flaw is unauthenticated, any visitor to the site could trigger the injection. Although the EPSS score is not available, the lack of a KEV listing does not diminish the immediate threat; the flaw can be exploited without additional conditions, making it a priority for remediation.
OpenCVE Enrichment