Impact
The vulnerability is an improper neutralization of special elements used in an SQL command, leading to blind SQL injection in the LambertGroup Radio Player Shoutcast & Icecast WordPress Plugin. A successful exploitation would allow an attacker to read data from the database; no explicit mention of data modification or deletion is provided in the description.
Affected Systems
LambertGroup Radio Player Shoutcast & Icecast WordPress Plugin is affected in all releases from the earliest available version through 4.4.6. Users of any version 4.4.6 or earlier must consider the plugin vulnerable.
Risk and Exploitability
With an EPSS score of less than 1% the overall likelihood of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. The high CVSS score and the blind nature of the SQL injection mean that an attacker who can reach the vulnerable input fields—potentially through unauthenticated access or via authenticated users—could extract sensitive data. The attack vector is inferred to be through the plugin’s exposed input endpoints, although the exact authentication requirements are not specified.
OpenCVE Enrichment
EUVD