Impact
Axiomthemes Smart SEO plugin for WordPress suffers from an improper neutralization of special elements used in an SQL command (CWE‑89). This flaw allows an attacker to inject arbitrary SQL statements into the backend query, potentially compromising the confidentiality and integrity of the database. The official CVSS score of 8.5 indicates high severity, meaning a successful exploitation would grant significant control over stored data.
Affected Systems
WordPress installations that use the Smart SEO plugin from Axiomthemes, version 4.0 or earlier. The vulnerability affects all releases from the initial version through 4.0; no later versions are listed as affected.
Risk and Exploitability
The EPSS score is less than 1 %, suggesting that the likelihood of exploitation observed in the wild is low at present. The issue is not listed in CISA’s KEV catalog. The flaw is exploitable through the web interface of the WordPress site; an attacker can send a crafted request to the plugin’s input processing endpoint to inject SQL. The vendor’s recommended remedy is to upgrade past 4.0; no temporary workaround has been provided by the CNA.
OpenCVE Enrichment