Impact
The vulnerability is an SQL injection flaw (CWE‑89) that allows an attacker to inject malicious SQL through the XV Random Quotes plugin. If exploited, the attacker could read, modify, or delete data in the WordPress database, which would compromise confidentiality, integrity, and potentially availability of the site.
Affected Systems
Affected is the XV Random Quotes plugin developed by Xavi Ivars, versions up to and including 2.0.0. WordPress sites running any of these versions are impacted.
Risk and Exploitability
The CVSS score of 9.3 indicates a high‑severity risk, and the EPSS score of less than 1% suggests a low probability of current exploitation, although the vulnerability is not listed in KEV. An attacker would likely send a crafted HTTP request containing malicious input to the plugin’s endpoint to exploit the flaw.
OpenCVE Enrichment
EUVD