Impact
The All In Menu plugin in WordPress versions up to 1.1.5 contains a blind SQL injection flaw that allows attackers to submit specially crafted input to extract data from the database. The weakness arises from improper neutralization of special elements in SQL commands, enabling unauthorized database reads or modifications. Successful exploitation could expose confidential user data or corrupt site content, severely impacting data confidentiality and integrity.
Affected Systems
WordPress sites that use cookforweb All In Menu plugin version 1.1.5 or earlier, including all releases from the first public version through to and including 1.1.5.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity vulnerability. The EPSS score of less than 1% suggests a low probability of active exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves submitting malicious input to the plugin’s endpoints over the web, leading to blind extraction of database information. The risk is elevated by the lack of input validation and the potential for data exposure.
OpenCVE Enrichment
EUVD