Impact
Improper neutralization of special elements in an SQL command allows an attacker to inject arbitrary SQL into the NC Wishlist for WooCommerce plugin. The vulnerability can enable reading, modifying or deleting database records, potentially exposing sensitive user data or allowing the attacker to alter site behavior. The weakness is identified as CWE‑89 and can result in significant confidentiality and integrity breach if exploited.
Affected Systems
WordPress installations that use the Crispweb NC Wishlist for WooCommerce plugin version 1.0.1 or earlier are affected. The issue applies to the plugin from its initial release up through 1.0.1, regardless of other WordPress components.
Risk and Exploitability
The CVSS score is 8.5, indicating high severity. The EPSS score is less than 1%, suggesting a low current exploitation probability, and the vulnerability is not yet listed in the CISA KEV catalog. Attackers are likely to exploit the flaw via web forms or AJAX endpoints that accept unsanitized input from site visitors. While the risk is moderated by the low exploitation likelihood, the potential impact warrants prompt remediation.
OpenCVE Enrichment
EUVD