Impact
The Facturante plugin for WordPress contains an improperly neutralized input that is incorporated directly into an SQL statement. This flaw, classified as CWE-89, allows an attacker to inject malicious SQL code that can read, modify, or delete database contents, potentially compromising sensitive data or enabling further attacks.
Affected Systems
WordPress sites running the Facturante plugin version 1.11 or earlier are vulnerable. "facturante:Facturante" is the affected product. The vulnerability extends through all releases up to and including version 1.11, with no fix included in the supplied versions.
Risk and Exploitability
The CVSS score of 9.3 indicates a high severity risk. The EPSS score of less than 1% suggests a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Inferred from the description, the attack vector is remote: an unauthenticated or authenticated attacker could trigger the injection via the plugin's exposed input fields over the web.
OpenCVE Enrichment
EUVD