Impact
Based on the CVE description, this flaw is an SQL Injection caused by improper neutralization of special characters. The primary impact is inferred as a data breach, allowing an attacker to read or modify the site’s database, potentially exposing user data, altering content, or escalating privileges. The weakness is catalogued as CWE‑89, which denotes injection vulnerabilities that bypass intended logic. Given the high CVSS of 8.5, an attacker who succeeds could compromise confidentiality and integrity of the site’s data.
Affected Systems
LambertGroup’s Multimedia Responsive Carousel with Image Video Audio Support plugin is affected for all releases up to and including version 2.6.0. No specific patch version is listed, so any installation using those versions is vulnerable.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity. The EPSS score is below 1 %, suggesting that, as of now, the likelihood of public exploitation is low. However, the plugin is web‑accessible and the flaw can be triggered remotely through the normal user interface; the likely attack vector is inferred to be remote via the plugin’s web interface. Because the plugin is not listed in CISA’s KEV catalog, it has not yet been confirmed in the wild. Administrators should treat the risk as high and take remedial action promptly.
OpenCVE Enrichment
EUVD