Impact
WPCHURCH plugin allows blind SQL injection via improper handling of user input, enabling an attacker to read, modify, or delete data from the underlying database. This vulnerability falls under CWE-89 and can compromise confidentiality, integrity, and availability of the site’s data.
Affected Systems
WordPress sites running Mojoomla WPCHURCH plugin versions up to and including 2.7.0 are affected. This includes any installation that has not yet updated beyond version 2.7.0.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity, while the EPSS score of less than 1% suggests a very low but non-zero likelihood of exploitation. The vulnerability is not listed in CISA KEV. Attackers can exploit the flaw by sending crafted HTTP requests to the plugin’s endpoints; the description infers that no special privileges are required beyond access to the site’s request handling.
OpenCVE Enrichment