Impact
Improper neutralization of special elements in SQL commands allows attackers to inject arbitrary SQL statements, leading to unauthorized read, write, or delete operations on the WordPress database. This can expose sensitive user data, credentials, and site content.
Affected Systems
Rainbow-Themes Education WordPress Theme | HiStudy in any deployment using a version prior to 3.1.0 is affected; the issue impacts the theme itself regardless of the underlying WordPress core version.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. With an EPSS score below 1%, the likelihood of exploitation is presently low, and the vulnerability is not listed in CISA KEV. However, the attack vector is inferred to be any user input or URL parameter handled by the theme, meaning that a malicious request could be crafted by an unauthenticated or authenticated user to perform injection.
OpenCVE Enrichment