Impact
Improper neutralization of special elements in an SQL command in the onOffice for WP-Websites plugin allows an attacker to inject arbitrary SQL statements. An injected query could read, modify, or delete database records, potentially exposing sensitive site data, compromising user accounts, or enabling further attacks within the web application.
Affected Systems
The vulnerability affects the onOffice for WP-Websites WordPress plugin provided by onOffice GmbH. Versions from the earliest release up through 5.7 are impacted. Users running 5.7 or older must update to a newer release where the issue is resolved.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity vulnerability. The EPSS score of less than 1% suggests that widespread exploitation is currently unlikely, and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers can likely reach the vulnerable code via the web interface of the plugin, and the exploitation does not appear to require authentication. The SQL injection can be used from remote addresses that can access the plugin’s endpoints.
OpenCVE Enrichment
EUVD