Impact
A stored SQL injection flaw exists in the Social Links plugin that allows an attacker to inject malicious SQL statements. The vendor names the issue as an improper neutralization of special elements, which can in turn lead to execution of arbitrary operating‑system commands through the database layer. If successful, the attacker can gain full control of the web server, compromise data confidentiality, integrity, and availability, and potentially pivot to other systems in the network.
Affected Systems
The Social Links plugin by kareemsultan, versions 1.2 and older, is affected.
Risk and Exploitability
The vulnerability has a CVSS score of 7.6, indicating a high severity. The EPSS score is reported as less than 1%, suggesting a low probability of exploitation in the near term, and the issue is not listed in the CISA KEV catalog. The likely attack vector is a web request to the plugin’s endpoints, from which an attacker could inject SQL statements that trigger arbitrary command execution on the server. Because the flaw can lead to total compromise, monitoring for unusual database activity and protecting against command execution mitigates the risk.
OpenCVE Enrichment
EUVD