Impact
The wp‑lead-capture plugin contains a blind SQL injection flaw caused by improper escaping of special characters in database queries, allowing an attacker to inject malicious SQL through user‑controlled inputs and pull or modify sensitive data, potentially compromising confidentiality and data integrity.
Affected Systems
All released versions of the WordPress WP Lead Capturing Pages plugin built by kamleshyadav up to and including 2.5 are affected. Upgrading to a newer version removes the vulnerability.
Risk and Exploitability
The CVSS score of 9.3 classifies this as a critical issue, yet the current EPSS score of less than 1% indicates low exploitation probability today. The flaw is not listed in CISA KEV, so no widespread exploitation is reported. The probable attack vector is through publicly accessible form fields processed by the plugin, though the exact exploitation pathway is inferred from the description.
OpenCVE Enrichment