Impact
Improper neutralization of special elements within an SQL command in Detheme Easy Guide enables an attacker to supply crafted input that is executed directly by the database. This flaw, classified as CWE-89, can lead to unauthorized reading, modification, or deletion of data stored in the WordPress database, potentially exposing sensitive site information or disrupting site functionality.
Affected Systems
The vulnerability affects the WordPress Easy Guide plugin supplied by Detheme. Any installation of the plugin that is at version 1.0.0 or lower is impacted; newer releases are not listed as affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.3, indicating a critical level of risk. The EPSS score is less than 1%, suggesting that the likelihood of exploitation is currently low, and the issue is not included in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is via the web interface of WordPress, where an attacker can submit malicious requests to the plugin’s endpoints. While exploitation probability remains low, the high severity warrants rapid action if the vulnerable version is in use.
OpenCVE Enrichment
EUVD