Impact
Improper neutralization of special elements is present in PickPlugins Wishlist, allowing an attacker to inject arbitrary SQL commands. The flaw is a classic SQL injection (CWE‑89) that can yield read, modify, or delete access to the WordPress database, potentially exposing sensitive user data or allowing further exploitation.
Affected Systems
The vulnerability afflicts the PickPlugins Wishlist WordPress plugin in all releases up to and including 1.0.41. No specific sub‑versions are listed beyond this upper bound, so any installation of 1.0.41 or earlier is vulnerable.
Risk and Exploitability
The CVSS score of 8.5 signifies high severity, yet the EPSS score of less than 1% suggests an uncommon exploitation likelihood. The plugin’s functionality is web‑based, so an attacker can contact the exposed endpoint(s) with crafted input. Because the flaw involves a standard SQL injection, any user possessing write access to the plugin forms, or potentially an unauthenticated user with form access, could leverage the flaw to compromise confidentiality and integrity of the database. The vulnerability is not listed in the CISA KEV catalog, indicating no known public exploits at this time.
OpenCVE Enrichment
EUVD