Impact
An attacker can exploit a SQL Injection vulnerability in the RJ Quickcharts plugin for WordPress when the input is not properly sanitized. By injecting malicious SQL statements into a crafted request, the attacker can read, modify, or delete database records. The vulnerability is classified as CWE‑89 and can potentially compromise the confidentiality, integrity, and availability of the site’s data.
Affected Systems
WordPress sites using the RJ Quickcharts plugin developed by randyjensen are affected. Versions from an undefined starting point up to and including 0.6.1 are vulnerable. Any site that has not upgraded beyond that version, or still hosts the affected plugin, is at risk.
Risk and Exploitability
The CVSS score of 8.5 indicates a high‑severity flaw, while the EPSS score of less than 1% suggests that real‑world exploitation attempts are currently rare. The vulnerability is not listed in the CISA KEV catalog. An attacker can potentially exploit the flaw by sending a crafted HTTP request to the WordPress site that includes the vulnerable input field. If the attack succeeds, the attacker may gain full database access, enabling theft or tampering of sensitive information.
OpenCVE Enrichment
EUVD