Impact
The WPDM – Premium Packages plugin for WordPress contains an improper neutralization of special elements used in an SQL command, allowing blind SQL injection. The flaw permits an attacker to read from or write to the database via crafted input that bypasses the plugin’s filtering, potentially compromising data confidentiality, integrity, and the overall security posture of the site. The vulnerability is identified as CWE-89 and is triggered when malicious payloads are sent to the plugin’s input vectors.
Affected Systems
Any WordPress site running the Shahjada WPDM – Premium Packages plugin version 5.9.6 or earlier is affected. The plugin is commonly used for managing digital product sales in WordPress environments.
Risk and Exploitability
The CVSS score of 7.6 indicates high severity, while an EPSS score of <1% reflects a very low but nonzero likelihood of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through HTTP requests to the plugin’s endpoints, with the attacker able to inject malicious SQL via tampered parameters. If exploited, an attacker could exfiltrate sensitive data or corrupt database contents, though the blind nature may require iterative probing.
OpenCVE Enrichment
EUVD