Impact
The flaw stems from improper neutralization of special elements used in an SQL command within the STEdb Forms plugin, which permits an attacker to inject arbitrary SQL statements. This capability could result in unauthorized disclosure, alteration, or erasure of data stored in the WordPress database by manipulating the plugin’s form processing logic.
Affected Systems
WordPress websites that have installed the STEdb Corp. STEdb Forms plugin in any version up to and including 1.0.4 are affected.
Risk and Exploitability
The CVSS score of 7.6 signifies a high severity vulnerability, while the EPSS score of less than 1% indicates a low probability of exploitation at present. The issue is not listed in the CISA KEV catalog, meaning no known active exploitation evidence exists. Based on the description, it is inferred that an attacker could exploit the flaw via publicly accessible form interfaces that pass user data to the database without proper sanitization, potentially without needing authentication. The combined impact and likelihood elevate the risk for any site running an affected plugin version.
OpenCVE Enrichment
EUVD