Impact
The vulnerability is a classic SQL injection flaw caused by improper neutralization of special characters in SQL statements within the Mailing Group Listserv WordPress plugin. An attacker can inject arbitrary SQL by submitting crafted input through the plugin’s public interfaces, potentially without needing authentication. This flaw can lead to unauthorized reading of sensitive data, modification of records, or even deletion of database contents, compromising the confidentiality, integrity, and availability of the site’s data. The weakness is identified as CWE‑89.
Affected Systems
WordPress installations that use the Yamna Khawaja Mailing Group Listserv plugin with any version up to and including 2.0.9 are affected. Any site that has not upgraded beyond 2.0.9 and still hosts this plugin is vulnerable.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity rating, while the EPSS score of less than 1% suggests that, as of now, the probability of widespread exploitation is low. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the plugin’s publicly accessible forms, where crafted input can be injected directly into SQL commands without the need for privileged credentials.
OpenCVE Enrichment
EUVD