Impact
The vulnerability resides in the Stylemix uListing WordPress plugin, where improper neutralization of special elements used in an SQL command allows an attacker to perform blind SQL injection. This flaw corresponds to CWE‑89 and can enable an attacker to read, or potentially modify, protected database content. The primary impact is the compromise of data confidentiality and integrity for the affected WordPress installation.
Affected Systems
The issue affects all installations of the uListing plugin from any unknown starting point through version 2.2.0. The plugin is supplied by Stylemix and is used within WordPress sites. Any site that has the v2.2.0 or earlier version deployed is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.6 classifies the vulnerability as high severity. The EPSS score of less than 1% indicates a low probability of active exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Based on the description it is inferred that the attack vector is through web-based input to the plugin’s exposed interfaces, and exploitation requires sending crafted payloads that trigger unescaped SQL evaluation. If successful, an attacker could extract sensitive data from the underlying database.
OpenCVE Enrichment
EUVD