Impact
Improper neutralization of special characters in an SQL command allows an attacker to inject arbitrary SQL when interacting with the WP Profitshare plugin. The CWE‑89 flaw can lead to unauthorized reading, modification, or deletion of database contents, compromising confidentiality, integrity, or availability of the site’s data.
Affected Systems
The vulnerability exists in ProfitShare.ro WP Profitshare plugin versions up to and including 1.4.9. WordPress sites that have been running any of these versions are impacted; newer plugin releases are not affected.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity, and the EPSS score of <1% suggests a low but non‑zero likelihood of exploitation in the wild. The plugin is a web‑accessible component, so the likely attack vector is a remote HTTP request bearing a crafted payload. The vulnerability is not listed in CISA’s KEV catalog, so no widespread, active exploits are documented.
OpenCVE Enrichment
EUVD