Impact
WordPress installations using the Nks Email Subscription Popup plugin up to version 1.2.23 are exposed to a blind SQL injection vulnerability caused by improper neutralization of SQL input. Attackers can insert crafted SQL statements through the plugin’s subscription interface, potentially allowing them to read, modify, or delete data stored in the WordPress database, thereby compromising confidentiality and integrity of site content.
Affected Systems
WordPress sites that have the Nks Email Subscription Popup plugin at any version earlier than or equal to 1.2.23 are affected. The plugin provides a publicly reachable subscription form or API endpoint that accepts user input without sufficient sanitization.
Risk and Exploitability
The CVSS score of 7.6 categorizes this flaw as high severity, while an EPSS of 36 percent indicates a moderate probability of exploitation in the wild. It is not listed in the CISA KEV catalog. The attack vector is inferred from the description to involve unauthenticated users sending crafted input through the subscription form or related API endpoint to trigger the blind SQL injection and extract or modify database records.
OpenCVE Enrichment