Impact
The vulnerability is an SQL injection flaw in the LETSCMS Binary MLM Plan WordPress plugin, affecting all released versions up to and including 3.0. The plugin incorporates user‑supplied input into database queries without proper neutralization, allowing an attacker to inject malicious SQL code. This can lead to unauthorized data disclosure, modification, or even execution of arbitrary SQL commands, compromising the confidentiality and integrity of the database.
Affected Systems
The affected product is the LETSCMS Binary MLM Plan plugin for WordPress, with affected releases ranging from an unspecified earliest version through version 3.0. The CVE data lists the lower bound as "n/a", so the specific minimum affected version is not identified. All releases up to 3.0 are considered vulnerable, and no later releases have been documented in the provided information.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity flaw, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, meaning no widespread exploits have been reported yet. Attackers are likely to exploit the plugin through exposed HTTP parameters or forms that the plugin processes, exploiting the lack of input validation to inject arbitrary SQL statements.
OpenCVE Enrichment
EUVD