Impact
Improper neutralization of special characters in a SQL command allows a remote attacker to inject arbitrary SQL queries through the JoomSky JS Help Desk WordPress plugin. This flaw permits unauthorized modification or disclosure of database contents, potentially leaking sensitive data or compromising the integrity of the entire site.
Affected Systems
The vulnerability affects the JoomSky JS Help Desk plugin for WordPress, inclusive of all releases up to and including 2.9.2. Sites running these versions are susceptible.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical impact, but the EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. An attacker could send crafted input through the plugin’s exposed endpoints, requiring no special privileges, to inject arbitrary SQL queries that could modify or expose database contents.
OpenCVE Enrichment
EUVD