Impact
The vulnerability is an improper use of SQL statements that allows an attacker to inject commands through form fields, a weakness classified as CWE-89. This can lead to blind extraction of data, manipulation of database records, and compromise of database confidentiality and integrity.
Affected Systems
WordPress sites using the Lead Form Data Collection to CRM plugin from Smackcoders Inc. with a version of 3.0.1 or earlier are affected; no later versions are known to remain vulnerable.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity with significant confidentiality and integrity impact. The EPSS score of less than 1% suggests a low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be through web form inputs that an attacker can control, enabling a blind SQL injection attack as described.
OpenCVE Enrichment
EUVD