Impact
The Catalyst Connect Zoho CRM Client Portal plugin for WordPress is vulnerable to a time‑based SQL injection through the uid parameter in all versions 2.2.0 and earlier. The lack of proper input escaping and query preparation permits an authenticated attacker with Administrator or higher privileges to append additional SQL statements to the existing query. This can lead to extraction of sensitive information from the database and compromise the confidentiality and integrity of the site.
Affected Systems
WordPress installations that have the Catalyst Connect Zoho CRM Client Portal plugin version 2.2.0 or earlier are affected. Exploitation requires an authenticated user with Administrator or higher privileges. Non‑elevated users cannot exploit the vulnerability, so the scope is limited to administrators and other privileged roles on the site.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate severity, while the EPSS score of < 1% reflects a low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is internal and requires authentication; after logging in as an elevated user, the attacker targets the uid parameter to inject malicious SQL. Successful exploitation would allow unauthorized data extraction from the WordPress database.
OpenCVE Enrichment