Impact
A flaw exists in the WordPress Entrada theme where unsanitized input is incorporated directly into SQL statements. The resulting SQL Injection can allow an attacker to execute arbitrary database commands. Depending on database privileges, this could lead to sensitive data extraction, modification, or even escalation of privileges within the site.
Affected Systems
The vulnerability affects the Waituk Entrada Theme for WordPress, versions up through 5.7.7. Users running any of those releases are potentially exposed.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.3, indicating high severity, while the EPSS score is under 1%, suggesting that exploitation is currently unlikely but still possible. It is not listed in the CISA KEV catalog, but the inherent risk of remote injection remains. The likely attack vector is remote, via crafted requests to the WordPress site that exploit the insecure SQL handling. Creation of malicious payloads through public interfaces could trigger the flaw without additional authentication.
OpenCVE Enrichment