Impact
Improper neutralization of special elements used in an SQL command, known as SQL injection, is present in AliRezaMohammadi دکمه، شبکه اجتماعی خرید dokme. When input data is passed directly to a database query without proper sanitization, an attacker can embed malicious SQL code. This flaw can allow extraction of sensitive information, alteration of database contents, or even elevation of privileges, compromising confidentiality, integrity, and potentially availability. The weakness is categorised as CWE‑89.
Affected Systems
Any WordPress site that has the AliRezaMohammadi دکمه، شبکه اجتماعی خرید plugin installed at version 2.0.6 or earlier is affected. The vulnerability applies to all older releases without an explicit patch, as indicated by the version range described in the advisory. The plugin is maintained by AliRezaMohammadi.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity flaw, while the EPSS score of less than 1% suggests low current exploitation probability. Because the vulnerability is triggered by user‑supplied input to the plugin, an unauthenticated attacker can potentially exploit it remotely by crafting malicious requests to the site. The flaw is not listed in CISA’s KEV catalogue, but the combination of high impact and community‑available advisory warrants swift action. Exploitation does not require any special credentials and relies solely on exposure through the website’s public interface.
OpenCVE Enrichment
EUVD