Impact
The vulnerability allows an attacker to execute arbitrary SQL commands due to improper neutralization of special elements in SQL statements. This flaw can enable the attacker to read, modify, or delete data stored in the database, potentially compromising sensitive user information or damaging the integrity of the site.
Affected Systems
WordPress sites running the RSVPMarker plugin by davidfcarr with versions up to and including 11.5.6 are affected. The plugin is included in the WordPress plugin repository and may be present on any site that has installed or is still using a version of RSVPMarker <= 11.5.6.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, and the EPSS score of < 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers would likely target the plugin through web input fields not properly validated, gaining remote database access if the application has unrestricted or high‑privilege database credentials.
OpenCVE Enrichment
EUVD