Impact
Improper neutralization of special elements within an SQL command, classified as CWE‑89, creates a blind SQL injection vulnerability in the Uxper Booking plugin up to version 1.3.3. An attacker who can supply crafted input can extract sensitive database content or modify data, leading to serious confidentiality and integrity risks.
Affected Systems
Any WordPress site running the Uxper Booking plugin version 1.3.3 or earlier is affected, regardless of site owner or user role, as the plugin’s code lacks proper input sanitization in its database interactions.
Risk and Exploitability
The CVSS score of 8.5 signals high severity, while an EPSS score below 1% suggests a low likelihood of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. It is inferred that the attack vector is remote through publicly exposed web endpoints, requiring the attacker to send crafted requests and interpret boolean or timing responses to infer database contents. No publicly available exploits are known, though the potential for data theft remains if an adversary can identify the vulnerable paths.
OpenCVE Enrichment
EUVD