Impact
An improper neutralization of special elements in SQL commands allows attackers to inject malicious SQL statements via the Falling Things plugin, which can result in unauthorized reading, modification, or deletion of database contents. The weakness is identified as CWE‑89. The impact is primarily data compromise rather than direct denial of service, with the severity reflected in a CVSS score of 7.6.
Affected Systems
The vulnerability affects the WordPress plugin Falling Things, version 1.08 or earlier, developed by manu225. Any WordPress site installing or keeping a vulnerable version of this plugin is at risk.
Risk and Exploitability
With an EPSS score below 1 % and no listing in CISA’s KEV catalog, the likelihood of exploitation is low, though the CVSS of 7.6 indicates significant potential impact if successfully exploited. The likely attack path involves the attacker submitting specially crafted input through the plugin’s interface, which is then used directly in SQL queries.
OpenCVE Enrichment
EUVD