Impact
WP Travel, a popular WordPress plugin, is affected by a classic SQL injection flaw. The plugin fails to properly neutralize special characters used in SQL commands, allowing an attacker to inject arbitrary SQL through vulnerable input fields. This can result in unauthorized data access, data modification, or potential escalation of privileges if the database holds sensitive information.
Affected Systems
All WordPress sites running WP Travel plugin version 10.1.3 or earlier are vulnerable. The issue spans from the first available release through version 10.1.3; any installation of these plugin versions on a WordPress environment is at risk.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity, while the EPSS score of less than 1% suggests a very low, but not zero, likelihood of exploitation at this time. It is not listed in CISA KEV. The likely attack vector is the plugin's exposed input endpoints, which may be reachable by unauthenticated users or users with minimal privileges. If exploited, the attacker could manipulate database contents, obtain confidential data, or compromise site functionality.
OpenCVE Enrichment
EUVD