Impact
Illegal manipulation of special characters within SQL statements can allow an attacker to inject arbitrary SQL commands into the WP HRM LITE plugin’s queries. This flaw falls under CWE‑89 and permits the attacker to read, modify or delete database records, thereby compromising confidential human‑resource data stored by the plugin.
Affected Systems
IndigoThemes WP HRM LITE WordPress plugin, any version up to and including 1.1. Any WordPress site that has not upgraded beyond 1.1 and still hosts the plugin is vulnerable. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 9.3 indicates a serious potential impact, but the EPSS score of less than 1% suggests a low current exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, via the plugin’s front‑end or back‑end interfaces that accept user input, and successful exploitation would grant the attacker unauthorized database access and possible data exfiltration.
OpenCVE Enrichment
EUVD