Impact
The Goodlayers Hotel plugin for WordPress contains a flaw where special characters in user input are not properly neutralized before being embedded in SQL queries, enabling blind SQL injection. This can allow attackers to retrieve, modify, or delete sensitive data stored in the WordPress database if the vulnerability is exploited. The weakness aligns with CWE‑89 and is rated high severity with a CVSS score of 9.3.
Affected Systems
Any WordPress site that has installed the Goodlayers Hotel plugin version 3.1.4 or earlier is susceptible. The vulnerability applies to all installations of the plugin that have not yet been updated beyond version 3.1.4.
Risk and Exploitability
Although the EPSS score is less than 1 percent, the high CVSS score indicates significant potential damage. The vulnerability is not listed in the CISA KEV catalog, but an attacker could exploit it via crafted HTTP requests targeting the plugin’s request handlers. Successful exploitation could lead to data theft or manipulation, presenting a considerable risk to affected sites.
OpenCVE Enrichment
EUVD