Impact
The vulnerability is an improper neutralization of special elements used in an SQL command, allowing an attacker to inject malicious SQL statements through the Gurmehub Kargo Entegratör WordPress plugin. This can lead to data exposure, modification, or deletion of database content, potentially compromising the entire website’s data store and all information it contains.
Affected Systems
Affected are WordPress sites running the Gurmehub Kargo Entegratör plugin, version 1.1.14 or earlier. All installations of the plugin in this version range are vulnerable, as the issue applies from the earliest tracked release through 1.1.14.
Risk and Exploitability
The CVSS score of 7.6 indicates a high risk of exploitation. The EPSS score of less than 1% suggests a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The description does not specify whether authentication is required, so it is inferred that an attacker would need to send a crafted request to an exposed input in the plugin; the exact attack vector cannot be confirmed from the supplied data.
OpenCVE Enrichment
EUVD