Impact
The vulnerability arises from improper neutralization of special characters in SQL commands within the SERPed.net WordPress plugin, allowing an attacker to inject arbitrary SQL statements. This flaw can lead to unauthorized reading or alteration of database contents, potentially compromising confidential user data or affecting site integrity.
Affected Systems
Vendors and products impacted are the SERPed.net WordPress plugin, version 4.4 and earlier, used by sites running WordPress.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity, yet the EPSS score of less than 1% suggests a low likelihood of exploitation at present. Although not listed in CISA KEV, the flaw can be triggered via web input fields processed by the plugin, giving attackers an avenue to execute SQL commands when the plugin processes user‑supplied data.
OpenCVE Enrichment
EUVD