Impact
Improper neutralization of special elements in the SQL command used by the Appsero Helper plugin allows an attacker to inject arbitrarily crafted SQL statements, potentially leading to unauthorized data exposure, modification, or even remote code execution. This weakness is identified as CWE-89 and poses a significant threat to the confidentiality, integrity, and availability of the WordPress site.
Affected Systems
The vulnerability affects the weDevs Appsero Helper plugin for WordPress, specifically versions up to and including 1.3.4. Any WordPress installation using the plugin in this range is at risk.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity level, while an EPSS score of less than 1% suggests the likelihood of exploitation is currently low, though the vulnerability is not listed in CISA’s KEV catalog. The attack vector is likely through the web interface of the plugin, where unsanitized user input is incorporated into SQL queries, enabling attackers to send malicious payloads remotely.
OpenCVE Enrichment
EUVD