Impact
The vulnerability is an improper neutralization of special elements used in an SQL command, identified as SQL injection (CWE-89). Attackers can supply crafted input that is not properly escaped, enabling direct manipulation of database queries. This can result in unauthorized data disclosure, modification, or deletion, and may provide a foothold for further exploitation such as remote code execution if additional weaknesses are present.
Affected Systems
The affected product is Quentn.com GmbH Quentn WP. All installations of the Quentn WP plugin with a version of 1.2.8 or earlier are impacted. No specific WordPress version is mentioned, so all WordPress sites using this plugin in the specified version range are vulnerable.
Risk and Exploitability
The assessed CVSS score is 9.3, indicating a high severity vulnerability. The EPSS score is listed as < 1%, implying a very low but nonzero exploitation probability at the time of the assessment. The vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is remote, via specially crafted requests to the plugin’s input handling endpoints, and an attacker does not need elevated privileges or local access to exploit the flaw.
OpenCVE Enrichment
EUVD