Impact
This vulnerability is an improper neutralization of special elements used in an SQL command, leading to SQL Injection. Attackers can inject arbitrary SQL via the online-accessibility plugin, allowing confidential data extraction, modification, or deletion and potentially full database compromise. The CWE-89 labeling indicates a classic SQL injection weakness that can be leveraged to subvert application logic.
Affected Systems
Ability, Inc Accessibility Suite WordPress plugin, versions from the earliest release through version 4.18. All installations of the plugin that have not been upgraded beyond 4.18 are susceptible.
Risk and Exploitability
The CVSS score of 8.5 classifies the issue as High severity. The EPSS score of <1% suggests that, at the time of this analysis, exploit attempts are extremely uncommon. The plugin is not listed in the CISA KEV catalog. Attackers would most likely reach the vulnerable input via the web interface, exploiting the plugin remotely.
OpenCVE Enrichment
EUVD