Impact
This flaw is an improper neutralization of special elements used in an SQL command, allowing an attacker to inject arbitrary SQL statements into the WordPress database. Through the vulnerable Easy Post Duplicator plugin, an attacker could read, modify, or delete database content, potentially exposing confidential site data or taking full control of the site’s content. The weakness is identified as CWE-89, indicating a failure of input validation and sanitization.
Affected Systems
WordPress sites running the Easy Post Duplicator plugin from the dev02ali distribution, up to and including version 1.0.1. All earlier versions are also impacted.
Risk and Exploitability
The CVSS score of 8.5 signals a high severity vulnerability. EPSS indicates a low exploitation probability (<1%), and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation activity. The likely attack vector is a remote request to the plugin’s administrative endpoint, where unsanitized input can be injected to manipulate SQL queries.
OpenCVE Enrichment
EUVD