Impact
The vulnerability stems from improper neutralization of special elements within an SQL command, allowing an attacker to inject arbitrary SQL. This can lead to unauthorized data access, modification, or deletion. The weakness is categorized as CWE‑89.
Affected Systems
The issue affects the Magic Responsive Slider and Carousel WordPress plugin from LambertGroup, specifically any installed version earlier than 1.6. Users running these versions are susceptible.
Risk and Exploitability
The CVSS score of 8.5 classifies this as a high‑severity flaw, yet the EPSS score is less than 1%, indicating a low probability of exploitation at present. It is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation yet. Based on the description, the likely attack vector is remote, whereby an attacker crafts malicious input through the plugin’s interface to trigger the SQL injection. Inference indicates that the flaw could be exploited by sending crafted requests to the plugin’s endpoints without authentication.
OpenCVE Enrichment
EUVD