Impact
Improper neutralisation of special characters in SQL commands allows an attacker to inject malicious SQL into requests processed by the Silvasoft boekhouden WordPress plugin. This flaw can be leveraged to read, modify, or delete data stored in the application database, potentially exposing sensitive information or altering financial records.
Affected Systems
The vulnerability affects the Silvasoft boekhouden plugin for WordPress, versions up to and including 3.0.6. Only installations of these versions are impacted; newer releases are not listed as affected.
Risk and Exploitability
The CVSS score of 7.6 describes a high severity level, while the EPSS score of less than 1% indicates a low current likelihood of exploitation. The flaw is not listed in CISA's KEV catalog. Attackers would likely target the plugin’s exposed endpoints through a web‑based attack vector, inserting malicious input into the plugin’s request handling logic.
OpenCVE Enrichment
EUVD