Impact
The vulnerability is an instance of improper neutralization of special elements used in an SQL command, allowing an attacker to inject arbitrary SQL statements. Damage can include theft or manipulation of database contents, privilege escalation, and denial of service. The weakness is identified as CWE-89, and it resides in the data handling routines of the plugin.
Affected Systems
WordPress sites that have the Local Magic plugin by Matthew Rubin installed, specifically versions using the plugin prior to and including 2.9.0. Any installation of Local Magic from its initial release up to version 2.9.0 is impacted.
Risk and Exploitability
The CVSS score of 9.3 places this flaw in the critical category, though the EPSS score of less than 1% suggests a currently low probability of exploitation. Based on the description, it is inferred that the plugin exposes the vulnerability via web interfaces that accept user input, allowing remote actors to craft malicious requests. The flaw is not listed in the CISA KEV catalog, yet the potential loss of data integrity and availability warrants immediate attention.
OpenCVE Enrichment
EUVD