Impact
The vulnerability is an SQL injection flaw that stems from unsanitized user input being incorporated directly into database queries. An attacker who can supply crafted values to certain plugin endpoints can execute arbitrary SQL commands. This could allow data extraction, modification, or even complete database compromise.
Affected Systems
WordPress sites that have the purethemes Listeo Core plugin with a version older than 2.0.7 are susceptible. The flaw exists in all releases prior to 2.0.7, with no specific sub‑version boundary indicated.
Risk and Exploitability
The CVSS score of 8.5 marks it as high severity, and the EPSS score of less than 1% indicates that exploitation is currently rare. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack vector is remote via the web interface and could be triggered by anyone who can send malicious requests to the site.
OpenCVE Enrichment
EUVD