Impact
In the WordPress plugin Google Maps Travel Route, special characters in SQL statements are not properly sanitized, allowing an attacker to inject arbitrary SQL. This flaw, classified as CWE‑89, can lead to unauthorized database access, data extraction, modification, or deletion, and potentially compromise the entire site’s data confidentiality and integrity.
Affected Systems
The vulnerability afflicts the traveller11 Google Maps Travel Route plugin for WordPress versions up to and including 1.3.1. Any WordPress installation that has this plugin installed at version 1.3.1 or earlier is susceptible.
Risk and Exploitability
With a CVSS score of 8.5 the flaw is considered high severity. The EPSS score of less than 1% indicates a low probability of observed exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is inferred to be network‑based, where an attacker crafts a malicious request to the plugin’s search or route endpoints to deliver the injected SQL. Once exploited, the attacker can read or modify database contents without authentication or with minimal privileges, depending on the site’s configuration.
OpenCVE Enrichment
EUVD