Impact
The PostMash plugin for WordPress is affected by an SQL Injection flaw where user-supplied data is inserted into a database query without proper escaping. An attacker can exploit this vulnerability to read, modify, or delete content stored in the database, potentially elevating privileges or compromising the entire WordPress site.
Affected Systems
The vulnerability affects the torsteino PostMash plugin version 1.0.3 and all earlier releases. WordPress installations that currently use this plugin without an update are at risk. No other vendors or product variants are listed.
Risk and Exploitability
The CVSS score of 9.3 signals critical severity, while an EPSS score of less than 1% indicates a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attack generally requires the ability to submit crafted input through the WordPress interface or API that reaches the vulnerable SQL query; once exploited, the attacker could gain full control over the database layer.
OpenCVE Enrichment
EUVD