Impact
Improper neutralization of special elements used in an SQL command leads to a vulnerable input in Solid Plugins AnalyticsWP, allowing an attacker to inject arbitrary SQL statements when untrusted data is directly incorporated into queries. Exploitation can enable reading, modification, or deletion of database contents, potentially compromising the integrity and confidentiality of the WordPress site and, in worst cases, allowing control of the underlying system.
Affected Systems
Solid Plugins:AnalyticsWP, a WordPress analytics plugin, is affected. The vulnerability exists in all releases up to and including version 2.1.2. The patch is available starting from version 2.1.5.
Risk and Exploitability
The CVSS score of 9.3 indicates a high severity, while the EPSS of less than 1% suggests that exploits are rare or nascent. The vulnerability is not yet listed in CISA KEV. Attackers likely exploit the plugin via unauthenticated web requests to the site, where malicious payloads are injected into query parameters or form submissions.
OpenCVE Enrichment
EUVD