Impact
The BSK Forms Blacklist plugin contains a Cross‑Site Request Forgery flaw that enables a malicious actor to inject arbitrary SQL code through a form submission. This blind injection can lead to unauthorized data exposure, modification, or deletion in the site database, potentially compromising user information or site integrity.
Affected Systems
WordPress sites running the bannersky BSK Forms Blacklist plugin, version 3.9 or earlier. The vulnerability was identified in all releases from the initial version up to 3.9 inclusive.
Risk and Exploitability
With a CVSS score of 8.2, the flaw is considered high severity. The EPSS score indicates a very low current exploitation probability (<1%), and it is not listed in the CISA KEV catalog. Inference suggests that the attack vector requires a user to be authenticated on the site or to have access to the plugin’s form handling endpoint, as the CSRF token is not properly verified, enabling the perpetrator to craft a harmful request.
OpenCVE Enrichment
EUVD