Impact
The Shipping for Nova Poshta plugin contains an SQL Injection flaw where user‑supplied data is embedded directly into a database query without proper sanitization. This flaw allows an attacker to inject arbitrary SQL statements, potentially gaining unauthorized read, modification, or deletion rights over the database schema. The impact is the compromise of confidentiality, integrity, and availability of all data persisted by the plugin.
Affected Systems
The vulnerable product is the WordPress Shipping for Nova Poshta plugin (nova‑poshta‑ttn) developed by Ihor Kit. All releases from the initial version through and including 1.19.6 are affected; later versions are unspecified.
Risk and Exploitability
The CVSS score of 9.3 classifies this flaw as critical. The EPSS score of less than 1 % indicates a low probability of exploitation at present, and the vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is remote, inferred from the fact that the plugin processes HTTP requests containing user input; an attacker can send crafted requests to the plugin’s endpoints to trigger the injection without needing authentication.
OpenCVE Enrichment
EUVD