Impact
The flaw is an improper neutralization of special elements within an SQL command, enabling an attacker to inject arbitrary SQL code. This can allow the execution of database queries beyond the intended scope, potentially exposing or altering sensitive data stored in the WordPress site's database.
Affected Systems
WordPress sites that run the Dourou Flickr set slideshows plugin version 0.9 or earlier are affected. The issue applies to all installations using this plugin regardless of WordPress core version, as the vulnerability resides in the plugin code itself.
Risk and Exploitability
The CVSS score of 8.5 reflects a high severity impact. The EPSS score is listed as less than 1%, indicating that an exploit is considered unlikely to be widely observed at the moment. The vulnerability is not included in the CISA KEV catalog. Exploitation would require an attacker to supply a crafted input to the plugin’s input handling routine via an HTTP request. While the low EPSS does not eliminate risk, the potential for data compromise warrants prompt remedial action.
OpenCVE Enrichment
EUVD