Impact
The CWD – Stealth Links WordPress plugin contains an SQL injection flaw where user-supplied data is incorporated into a database query without proper sanitization. If exploited, an attacker could inject arbitrary SQL, potentially acquiring sensitive data or executing arbitrary code on the database server, which in turn may lead to full site compromise.
Affected Systems
This vulnerability affects the Caio Web Dev CWD – Stealth Links plugin for WordPress, versions up through 1.3. Any WordPress site that has this plugin installed and is running a vulnerable version is susceptible.
Risk and Exploitability
The flaw carries a CVSS score of 9.3, indicating critical severity. The EPSS score is < 1%, suggesting low but non-zero likelihood of exploitation in the wild. The vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector is remote via the plugin’s publicly accessible interfaces, allowing a remote attacker to exploit the weakness.
OpenCVE Enrichment
EUVD