Impact
Improper neutralization of special elements used in an SQL command allows an attacker to perform blind SQL injection against WP Multistore Locator. The flaw can lead to extraction, modification, or deletion of data stored in the WordPress database, compromising confidentiality and integrity of sensitive information. The vulnerability is classified as CWE-89.
Affected Systems
The flaw affects WPExperts.io WP Multistore Locator plugin versions up to and including 2.5.1 on WordPress sites. No specific lower bound is given, so all versions from the earliest available release through 2.5.1 are considered vulnerable.
Risk and Exploitability
The CVSS score of 9.3 categorizes the vulnerability as critical. However, the EPSS score of less than 1% indicates a very low current exploitation probability. The plugin is exposed via the web interface, making a remote attacker the most likely vector; authentication is not required to reach the injection point. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
EUVD