Impact
Improper Neutralization of Special Elements used in an SQL Command allows an attacker to inject arbitrary SQL into queries processed by the History Log by click5 plugin. The flaw arises from unsanitized user input being incorporated directly into a database statement. Successful exploitation can lead to data disclosure, data manipulation, or even escalation of privileges within the application, depending on the underlying database account permissions.
Affected Systems
The vulnerability affects the History Log by click5 WordPress plugin versions 1.0.13 and earlier released by click5. No other vendors or versions are listed as impacted.
Risk and Exploitability
The CVSS score of 9.3 reflects a high severity with remote exploitation possible. The EPSS score of less than 1% indicates a low probability of exploitation at the moment, but the vulnerability is not listed in the CISA KEV catalog. Attackers could reach the injection point via typical plugin interfaces exposed to users with sufficient WordPress roles, making the threat relevant for sites with the plugin installed and not yet patched.
OpenCVE Enrichment
EUVD