Impact
The vulnerability is an SQL Injection flaw caused by improper neutralization of special elements in an SQL command within the Slim SEO WordPress plugin. An attacker could inject malicious SQL through unsanitized input, potentially allowing read or write access to the database. This could lead to data theft, corruption, or unauthorized modification of website content. The weakness is identified as CWE-89.
Affected Systems
The Slim SEO plugin by Anh Tran is affected in all releases up to and including version 4.5.4.
Risk and Exploitability
The CVSS score of 7.6 indicates high severity. The EPSS score of less than 1% suggests that exploitation is currently low probability, but not impossible, and the vulnerability is not listed in CISA's KEV catalog. Likely, an attacker could exploit the flaw remotely by sending crafted HTTP requests to the plugin's entry points; however, specific conditions such as authentication or lack thereof are not detailed in the data. Given the high impact if exploited, organizations should prioritize applying a fix or mitigating measures.
OpenCVE Enrichment
EUVD