Impact
The vulnerability is an untrusted input flaw that allows attackers to inject arbitrary SQL through the Flickr set slideshows WordPress plugin. The flaw resides in improper neutralization of special characters used in SQL commands, consistent with CWE‑89. An attacker who can submit malicious input to the plugin can read, modify, or delete data stored in the WordPress database, causing a loss of confidentiality and integrity of site data.
Affected Systems
The affected product is the Dourou Flickr set slideshows plugin for WordPress, versions from the initial release through 0.9 inclusive. Systems running any of these versions of the plugin are vulnerability susceptible.
Risk and Exploitability
The CVSS score of 8.5 indicates a high-severity risk, while the extremely low EPSS (<1%) suggests that widespread exploitation is unlikely at present. The vulnerability is not listed in CISA’s KEV catalog. Attackers would likely target the plugin via the web interface, exploiting a lack of input validation to inject SQL. If successful, the attacker could execute arbitrary SQL queries against the WordPress database, gaining unauthorized data access or control.
OpenCVE Enrichment
EUVD