Impact
The Ai Auto Tool Content Writing Assistant plugin contains an improper neutralization of special elements in an SQL command, enabling blind SQL injection. An attacker can supply crafted input to read or modify the site’s database, potentially exposing sensitive data or altering content. The flaw is categorized as CWE‑89.
Affected Systems
WordPress sites using the Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT All in One) plugin version 2.2.6 or earlier are affected.
Risk and Exploitability
The CVSS score of 8.5 marks this as a high‑severity vulnerability. EPSS indicates a very low (but non‑zero) likelihood of exploitation, and it is currently not listed in the CISA KEV catalog. The attack vector is likely through web input to the plugin’s endpoints without requiring special authentication; the blind nature means an attacker may need to infer results via timing or error responses.
OpenCVE Enrichment
EUVD