Impact
This vulnerability arises from improper neutralization of special elements in SQL commands within the Ultimate Push Notifications plugin. The flaw permits attackers to inject and execute arbitrary SQL statements through crafted input, potentially enabling read, modification, or deletion of database data and compromising both data confidentiality and integrity.
Affected Systems
The issue affects the CodeSolz Ultimate Push Notifications WordPress plugin version 1.2.0 and earlier. All installations running these versions are vulnerable. No specific sub‑versions are listed beyond the ≤ 1.2.0 boundary.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity level, while the EPSS score of <1% suggests the probability of exploitation is low at present, and the vulnerability is not in CISA's KEV catalog. Likely the plugin accepts user input from publicly accessible URLs or forms; the injection can be triggered remotely by sending malicious payloads via the web interface, as inferred from the nature of SQL injection within a WordPress plugin.
OpenCVE Enrichment
EUVD