Impact
The vulnerability is a classic SQL injection flaw in the Ads by WPQuads plugin, allowing an attacker to improperly neutralize special elements within an SQL command. This flaw can result in unauthorized data manipulation, leakage, or modification of database content, impacting the entire WordPress site.
Affected Systems
Vulnerable installations of the Ads by WPQuads plugin up to version 2.0.87.1 are impacted. Any WordPress site running this plugin in the specified version range is at risk.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. The EPSS score of less than 1% suggests the exploit is not yet common, but the flaw remains available to adversaries with sufficient skill. The vulnerability is not listed in the CISA KEV catalog. It can be exploited through web interfaces that accept user input and construct SQL queries without adequate sanitization, likely requiring authenticated user privileges or public access depending on plugin configuration.
OpenCVE Enrichment
EUVD