Impact
An attacker who can send crafted requests to the WP Employee Attendance System plugin could exploit a blind SQL injection flaw. The vulnerability arises from insufficient sanitization of user input when forming SQL commands. This could allow extraction of sensitive database information or modifications, threatening confidentiality and integrity of the attendance data.
Affected Systems
The issue affects the Suhas Surse WP Employee Attendance System plugin for WordPress through version 3.5. Any WordPress site running this plugin version is potentially vulnerable until a newer release is available.
Risk and Exploitability
The CVSS score of 7.6 classifies the vulnerability as high severity. The EPSS score of less 1% indicates a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Likely attack vectors involve remote exploitation via the plugin's exposed endpoints within a WordPress installation; an attacker could send specially crafted requests from outside the network to trigger the blind injection.
OpenCVE Enrichment
EUVD