Impact
The vulnerability is an SQL injection flaw in the woobewoo WBW Product Table PRO plugin. It allows an attacker to inject arbitrary SQL code into database queries, potentially reading, modifying, or deleting data. This can compromise the confidentiality, integrity, or availability of data stored by the WordPress site.
Affected Systems
All installations of the WBW Product Table PRO WordPress plugin by woobewoo with versions from the earliest release through and including 2.2.6. Any WordPress site that has such a version deployed and exposed to the public Internet is vulnerable.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity, though the EPSS score is under 1%, which suggests a low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the flaw by sending unauthenticated web requests to the plugin’s query handling endpoints with crafted input, which can lead to arbitrary SQL execution and potentially full database compromise and further remote code execution if the database credentials are used to interact with the underlying system.
OpenCVE Enrichment
EUVD