Impact
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in the web-mv ResAds plugin allows attackers to inject arbitrary SQL through properly crafted input. The flaw affects all releases up to and including version 2.0.5. Successful exploitation could read, modify, or delete database data, compromising the site’s content and potentially exposing sensitive user information.
Affected Systems
The vulnerability exists in ResAds developed by web‑mv. Any WordPress site that has ResAds 2.0.5 or earlier installed is impacted; versions newer than 2.0.5 are not affected.
Risk and Exploitability
The CVSS score of 7.6 denotes high severity, while the EPSS score of less than 1% indicates a low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, likely through unauthenticated HTTP requests to a plugin endpoint that accepts user input, and compromise would result in loss of confidentiality and integrity for the site’s database contents.
OpenCVE Enrichment
EUVD