Impact
The vulnerability is a classic SQL Injection flaw caused by improper neutralization of special elements in an SQL command within the CHATLIVE plugin. An attacker can inject arbitrary SQL statements, potentially exposing, modifying or deleting database contents and possibly executing arbitrary code if database privileges allow. This flaw is classified as CWE‑89 and places the plugin under high risk for data confidentiality and integrity breaches.
Affected Systems
Affected systems include the WordPress CHATLIVE plugin by Claudio Adrian Marrero, any instance from its early releases up to and including version 2.0.1. No additional vendor or product versions are listed, so any WordPress site using the plugin at or below this version is vulnerable.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity, while the EPSS score of less than 1% suggests a low but non‑zero likelihood of exploitation. The vulnerability is not present in CISA’s KEV catalog. Exploitation can occur through the web interface that accepts plugin input; provided an attacker can reach the vulnerable endpoint, no special authentication requirements are documented, implying that unauthenticated remote execution is feasible.
OpenCVE Enrichment
EUVD