Impact
This vulnerability allows a blind SQL injection attack caused by improper neutralization of special elements in SQL commands used by the Video Player & FullScreen Video Background plugin. An attacker can manipulate database queries, potentially extracting sensitive data or modifying database contents, leading to confidentiality and integrity breaches.
Affected Systems
The vulnerability affects all versions of the LambertGroup Video Player & FullScreen Video Background plugin up to and including version 2.4.1.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity level, though the EPSS score of less than 1% suggests a low probability of exploitation currently. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through a web request that the plugin processes, as inferred from the nature of the injection, though a specific method is not detailed in the data.
OpenCVE Enrichment
EUVD