Impact
The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'coating_text' parameter due to inadequate escaping and missing preparation of the SQL command. Attackers can inject malicious SQL fragments, allowing them to execute arbitrary queries and retrieve confidential data from the database. The weakness is a classic SQL Injection vulnerability (CWE‑89).
Affected Systems
All instances of the 3DPrint Lite WordPress plugin with version 2.1.3.6 and earlier are affected. The plugin is distributed by fuzzoid. Any WordPress site running these versions of the plugin is at risk.
Risk and Exploitability
The CVSS base score of 4.9 indicates moderate severity, and the EPSS score being below 1% suggests a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Although the original description indicates unauthenticated attackers can exploit the flaw, the vulnerability requires the ability to send crafted HTTP requests containing the 'coating_text' parameter; thus, the most likely attack vector is via web traffic from external actors. An attacker with network access to the site could automate repeated injection attempts to enumerate data.
OpenCVE Enrichment
EUVD