Impact
The vulnerability is an SQL injection flaw in the MindValley Super PageMash WordPress plugin, arising from the improper neutralization of special characters in SQL commands. Exploitation could allow an attacker to read, modify or delete data from the database, potentially leading to unauthorized data access and integrity compromise. The weakness maps to CWE‑89, indicating unchecked input reaches database queries.
Affected Systems
Affected product: MindValley Super PageMash plugin for WordPress, versions from the earliest build through version 1.1. Users running any of these versions are vulnerable until upgraded.
Risk and Exploitability
The CVSS score of 7.6 classifies the risk as high, while the EPSS score of less than 1% shows a very low but non–zero probability of current exploitation. The vulnerability is not listed in CISA's KEV catalog, which suggests limited known exploitation. Likely attack vector is remote through the WordPress web interface, possibly unauthenticated depending on plugin configuration, as the flaw exists in a publicly accessible plugin component.
OpenCVE Enrichment
EUVD