Impact
An attacker can inject malicious SQL through an unsanitized input field in the Stylemix uListing plugin. The vulnerability, classified as a blind SQL injection, allows unauthorized extraction of data from the WordPress database. This flaw results from improper neutralization of special characters in SQL commands, enabling attackers to read sensitive information such as user credentials or business data stored in the site.
Affected Systems
WordPress sites that run the Stylemix uListing plugin version 2.1.6 or earlier. Any installation that has not been upgraded beyond this point is vulnerable, regardless of other security controls.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical risk. The EPSS score is below 1 %, suggesting a low probability of exploitation in the near term, and the vulnerability is not listed in the CISA KEV catalogue. Nevertheless, the blind nature of the attack allows data disclosure if successful. The likely attack vector is a remote web interface that accepts user input for listing management, permitting an attacker to send crafted payloads to the plugin.
OpenCVE Enrichment
EUVD