Impact
An SQL injection flaw exists in WP Marka WordPress Auction Plugin up to version 3.7. Because the plugin fails to properly neutralize special characters in SQL commands, an attacker may supply crafted input that is executed by the database engine. This weakness can lead to unauthorized data reading, modification, or deletion, potentially allowing an attacker to compromise the integrity and confidentiality of the site’s database.
Affected Systems
The vulnerability affects the WordPress Auction Plugin (WP Marka) for all installations using version 3.7 or older. This includes any WordPress site that has the plugin enabled without applying the available fix.
Risk and Exploitability
The CVSS score of 7.6 indicates a moderate to high impact. The EPSS score of less than 1% suggests that, at the time of analysis, the probability of exploitation is low, and the vulnerability is not listed in CISA’s KEV catalog. Likely exploitation would occur via a web request to the plugin’s input fields, where malicious SQL payloads can be injected through unsanitized user input.
OpenCVE Enrichment
EUVD