Impact
The WOOEXIM WordPress plugin from bulktheme contains an SQL injection flaw that allows an attacker to insert arbitrary SQL statements. By exploiting this weakness, the attacker can read, modify, delete, or exfiltrate data from the database, potentially compromising the entire site.
Affected Systems
This affects the bulktheme WOOEXIM plugin for WordPress, versions up to and including 5.0.0. Any WordPress installation that has not updated beyond 5.0.0 is vulnerable.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity vulnerability, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The flaw is not listed in the CISA’s KEV catalog. The likely attack vector is through the web interface of the plugin, enabling remote attackers to send crafted requests that cause SQL commands to run.
OpenCVE Enrichment
EUVD