Impact
Improper validation of user-supplied input allows an attacker to inject arbitrary SQL commands into queries executed by the plugin. The flaw could enable unauthorized reading, alteration, or deletion of data stored in the database, leading to possible breach of data confidentiality and integrity.
Affected Systems
LambertGroup Responsive HTML5 Audio Player PRO With Playlist, all installations up to and including version 3.5.7.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, while the EPSS score of less than 1% suggests that exploit attempts have so far been rare. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require sending a specially crafted HTTP request to a vulnerable endpoint exposed by the plugin, which is typically accessible through normal web traffic. Although the attack vector is likely remote, the low EPSS indicates that it has not yet been widely abused.
OpenCVE Enrichment
EUVD