Impact
Improper neutralization of special elements in an SQL command enables attackers to inject malicious SQL statements. The vulnerability, identified as CWE-89, can lead to unauthorized data disclosure, alteration, or deletion within the WordPress database. The impact extends to loss of confidentiality, integrity, and potential disruption of services if critical data is compromised.
Affected Systems
The affected product is the Metagauss ProfileGrid WordPress plugin for all releases from the earliest version through 5.9.5.0. Users running any version of ProfileGrid ≤ 5.9.5.0 are susceptible unless they upgrade to a newer release.
Risk and Exploitability
The CVSS score of 8.5 reflects high severity, while the EPSS score of < 1% indicates a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Attackers would likely exploit it via remote HTTP requests to the WordPress site, sending crafted input that bypasses the plugin’s sanitization and injects SQL code into backend queries.
OpenCVE Enrichment
EUVD