Impact
The flaw is an improper neutralization of special elements in an SQL command, allowing an attacker to inject arbitrary SQL through the WP Pipes plugin. This could enable reading, modifying, or deleting user data, compromise authentication, and potentially disrupt site functionality, affecting confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects the ThimPress WP Pipes plugin for WordPress installations utilizing any version up to and including 1.4.3. All installations of WP Pipes that have not applied the latest update are susceptible.
Risk and Exploitability
With a CVSS score of 9.3, the risk is high, but the EPSS score of less than 1% indicates that exploitation is currently unlikely in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require a user to supply crafted input to the plugin, which in practice could occur through the plugin’s public or authenticated input interfaces. A successful attack could give an adversary full control of the WordPress database linked to the site.
OpenCVE Enrichment
EUVD