Impact
The WP Lead Capturing Pages plugin for WordPress contains a critical SQL injection flaw that allows an attacker to insert untrusted input into database queries without proper escaping. This vulnerability is a blind SQL injection, giving the attacker the ability to read or modify data stored by the plugin. Consequently, visitor information and other sensitive data can be exfiltrated or corrupted, leading to significant confidentiality and integrity compromises.
Affected Systems
The issue affects the kamleshyadav WP Lead Capturing Pages plugin for WordPress, specifically versions up to and including 2.5. No other product versions are listed as affected.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, and the EPSS score of less than 1% indicates that, as of the assessment, exploitation is not widely observed but still possible. The vulnerability is not listed in the CISA KEV database, suggesting no confirmed exploitation, but the risk remains due to the high impact. The likely attack vector involves submitting crafted input to the plugin’s form or endpoint, which is processed by an unparameterized SQL query. No explicit authentication requirement is mentioned, so the flaw is potentially exploitable by unauthenticated users.
OpenCVE Enrichment