Impact
The flaw permits arbitrary SQL execution. As a CWE‑89 SQL Injection vulnerability, it allows an attacker to inject special characters into an SQL command used by the WPAMS plugin, thereby potentially reading, modifying, or deleting database contents and compromising confidentiality, integrity, and availability.
Affected Systems
The issue affects the WPAMS apartment‑management plugin distributed by mojoomla, and applies to all releases from the earliest version through version 44.0 (released 17‑08‑2023). Any WordPress site that has this plugin installed is potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.5 categorises the vulnerability as high‑severity, and the EPSS score of less than 1% indicates a very low current exploitation probability. The flaw is not listed in the CISA KEV catalog. The likely attack vector is through the plugin’s publicly accessible endpoints or API calls that accept user input. Based on the description and typical plugin exposure, this could be exploitable by unauthenticated or authenticated users, depending on the site configuration.
OpenCVE Enrichment
EUVD