Impact
This injection flaw, identified as CWE-89, permits attackers to insert malicious SQL statements into queries constructed by the WP Guppy plugin, potentially allowing them to read, alter, or delete data stored in the website database, thus compromising confidentiality, integrity, and availability of site data.
Affected Systems
The vulnerability affects the AmentoTech WP Guppy WordPress plugin, versions from the earliest release up to and including 4.3.3. All WordPress sites running these versions are potentially vulnerable until an update or removal of the plugin.
Risk and Exploitability
The issue carries a CVSS score of 8.5, indicating high severity, but its EPSS score is below 1%, suggesting low current exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely via any publicly accessible request that processes user input, such as plugin configuration or front‑end forms, enabling remote attackers to deliver malicious SQL without authentication.
OpenCVE Enrichment
EUVD