Impact
Improper neutralization of special elements in a SQL command allows an attacker to inject arbitrary SQL statements into the WP Sitemap plugin’s database queries. This flaw can compromise data confidentiality and integrity, potentially enabling unauthorized data exfiltration or modification of site content. The vulnerability is classified under CWE‑89 and carries a CVSS score of 8.5, indicating a high severity risk.
Affected Systems
The vulnerability affects the WordPress WP Sitemap plugin supplied by Jenst. Any installation where the plugin version is unchanged or any unknown version from the earliest release through version 1.0 is considered vulnerable.
Risk and Exploitability
The EPSS score is reported as less than 1 %, suggesting that exploitation opportunities are currently limited, yet the flaw remains publicly disclosed and could be leveraged by an attacker who can manipulate the plugin’s input parameters. As the plugin operates through the WordPress front‑end, the attack vector is likely through standard HTTP requests containing crafted input. The flaw is not listed in the CISA KEV catalog and has no known public exploit at this time, but the high CVSS score denotes a significant potential impact if exploited.
OpenCVE Enrichment
EUVD