Impact
The Amely theme, revision 3.1.4 or earlier, contains an improper neutralization of special elements used in an SQL command that allows an attacker to build a malicious SQL query. Because the theme fails to properly escape user‑supplied input, an attacker can insert arbitrary SQL statements into the database. This could lead to unauthorized disclosure of sensitive data, modification of the database contents, and in extreme cases, full compromise of the WordPress site’s data layer. The weakness is classified as CWE‑89.
Affected Systems
WordPress sites that are running the ThemeMove Amely theme version 3.1.4 or below are impacted. The vulnerability affects any installation that has the theme active, as the code paths are present in all versions up to 3.1.4.
Risk and Exploitability
The vulnerability is scored with a CVSS base score of 9.3, indicating critical severity. The EPSS score is reported as less than 1 %, showing a low probability of exploitation in the general population, but the weakness is publicly known and could be exploited remotely by sending crafted HTTP requests to the affected theme pages. The vulnerability is not listed in the CISA KEV catalog, meaning no known active exploits have been reported yet. Still, the potential of data loss warrants immediate remediation.
OpenCVE Enrichment
EUVD