Impact
The Easy Query – WP Query Builder plugin improperly neutralizes special characters in SQL commands, allowing a blind SQL injection attack. An attacker can manipulate database queries to leak sensitive information or alter data, compromising confidentiality and integrity under CWE‑89.
Affected Systems
All WordPress sites using the Easy Query – WP Query Builder plugin version 2.0.4 or earlier are affected. The vulnerability applies to any installation that has the plugin enabled.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity, but the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is a web‑based request to the plugin’s exposed endpoints, which an attacker might discover through blog or forum posts.
OpenCVE Enrichment
EUVD