Impact
Improper neutralization of special elements in an SQL command permits an attacker to inject arbitrary SQL. This flaw can allow unauthorized reading, modification, or deletion of database content, compromising confidentiality, integrity, and potentially availability of data served by the plugin.
Affected Systems
The vulnerable product is the WordPress Plugin ‘Nearby Locations’ by aaronfrey, affecting all releases from the earliest version through 1.1.1. This includes any WordPress site installing or updating to these versions of the plugin.
Risk and Exploitability
With a CVSS score of 7.6, the vulnerability poses a high risk. The EPSS indicates a below‑1% exploitation probability, and the flaw is not listed in CISA KEV, suggesting limited current exploitation events. The likely attack vector is through the plugin’s web-facing interface, where crafted input can be injected into SQL queries without proper sanitization. An attacker exploiting this flaw can execute arbitrary SQL commands against the site’s database.
OpenCVE Enrichment
EUVD