Impact
The Social Share And Social Locker plugin contains an unchecked input that allows an attacker to perform blind SQL injection. This flaw can be exploited to read or alter database contents, potentially exposing sensitive data or modifying site data. The vulnerability is a classic example of poor input validation, classified as CWE-89.
Affected Systems
The affected product is reputeinfosystems Social Share And Social Locker for WordPress. Versions from the initial release through and including 1.4.2 are vulnerable. No other versions are listed as affected.
Risk and Exploitability
With a CVSS score of 9.3 the flaw is considered critical. The EPSS score of less than 1% suggests a low likelihood of public exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. Attackers can target the plugin via the WordPress web interface, sending crafted requests that trigger the blind SQL injection; this likely attack vector is inferred from the plugin's exposed input fields. Successful exploitation would grant an attacker unauthorized access to database data.
OpenCVE Enrichment
EUVD