Impact
A flaw in GoodLayers Goodlayers Hostel allows Blind SQL Injection by improperly neutralizing special characters in SQL commands. If exploited, an attacker could extract, modify, or delete database contents, compromising confidentiality, integrity, and potentially availability of the site’s data.
Affected Systems
GoodLayers Goodlayers Hostel plugin for WordPress, versions from the initial release up to and including 3.1.4, is affected.
Risk and Exploitability
The vulnerability has a CVSS score of 9.3 indicating a high severity situation, but the EPSS score of < 1% suggests that real‑world exploitation is unlikely at this time. It is not listed in CISA’s KEV catalog. The likely attack vector is a crafted HTTP request to the plugin’s public endpoint, possibly without authentication, that injects SQL code to extract data. Even though the probability is low, the impact would be significant, requiring prompt mitigation.
OpenCVE Enrichment
EUVD