Impact
Improper neutralization of special elements in an SQL command allows an attacker to inject malicious SQL through the Md Yeasin Ul Haider URL Shortener plugin. Such injection could enable an adversary to read, modify, or delete data stored in the WordPress database, potentially exposing sensitive information or disrupting site operation. The vulnerability is listed as a high severity (CVSS 9.3) and is present in all releases of the plugin up to and including version 3.0.7.
Affected Systems
This issue affects the WordPress plugin 'URL Shortener' (exact-links) distributed by Md Yeasin Ul Haider. All installed instances with a version of 3.0.7 or earlier are impacted.
Risk and Exploitability
The EPSS score of less than 1% suggests a low likelihood of exploitation yet the CVSS score of 9.3 indicates a critical impact if exploited. The vulnerability is not listed in the CISA KEV catalog. Attackers likely need internet-accessible access to a WordPress site using the vulnerable plugin, and may exploit it by crafting malicious inputs in the plugin’s URL structures or form data to execute arbitrary SQL commands.
OpenCVE Enrichment
EUVD