Impact
The vulnerability is an improper neutralization of special elements used in an SQL command, classified as CWE‑89. The WordPress YaySMTP plugin allows an attacker to inject arbitrary SQL through unsanitized input, potentially enabling data exfiltration or modification and compromising the integrity of the site.
Affected Systems
YayCommerce’s YaySMTP WordPress plugin, versions through 1.3, is affected. The issue exists in all releases up to and including 1.3.
Risk and Exploitability
The CVSS score is 7.6, indicating high severity. The EPSS score is less than 1%, suggesting very low current exploitation likelihood. The vulnerability is not listed in CISA KEV. The likely attack vector is via the plugin’s web interface, where crafted input can be submitted to trigger the injection. Successful exploitation would require the attacker to have network access to the WordPress site and the ability to send requests to the affected endpoint.
OpenCVE Enrichment
EUVD