Impact
The vulnerability is an improper neutralization of special elements used in an SQL command (CWE‑89). It allows attackers to inject arbitrary SQL statements through the Multiple Carousel plugin’s input handling, potentially retrieving or modifying sensitive data stored in the WordPress database over the web interface.
Affected Systems
WordPress sites that have the Multiple Carousel plugin version 2.0 or older installed, regardless of other components.
Risk and Exploitability
The CVSS score of 9.3 indicates a high severity of the flaw. The EPSS score is below 1%, suggesting a low exploitation probability in the short term, and the vulnerability is not listed in CISA KEV. Nevertheless, the plugin processes user input via SQL commands, so an attacker with web access that can reach vulnerable input fields can exploit the flaw. The attack vector is inferred to be remote over the public web interface, requiring only the ability to submit crafted input to the plugin’s endpoints.
OpenCVE Enrichment
EUVD