Impact
WP Multistore Locator allows attackers to inject arbitrary SQL commands by exploiting improper neutralization of special elements used in SQL statements. This flaw, classified as CWE-89, permits an attacker to read, modify, or delete database contents, leading to confidentiality, integrity, and availability impacts such as data theft or loss.
Affected Systems
The vulnerability affects the WP Multistore Locator plugin from WPExperts.io for all releases up to and including version 2.5.2. Any WordPress installation running this plugin on a database back-end is exposed until the plugin is updated beyond the listed version threshold.
Risk and Exploitability
With a CVSS score of 9.3, the flaw is considered critical. The EPSS score of less than 1% suggests that, so far, exploitation is unlikely, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is a remote attacker sending crafted HTTP requests to vulnerable plugin endpoints that accept user input without proper escaping, enabling manipulation of underlying SQL commands.
OpenCVE Enrichment
EUVD