Impact
The Classiera WordPress theme contains an improper neutralization of special elements used in an SQL command, enabling attackers to inject arbitrary SQL statements. This flaw, classified as CWE‑89, can be used to read, modify, or delete data directly from the database. An attacker who successfully exploits the vulnerability could gain full control over the application's data layer, potentially leading to data exfiltration or destruction.
Affected Systems
The vulnerability affects the JoinWebs Classiera theme in all releases up to and including 4.0.34. Systems running any of those versions, regardless of the WordPress core version, are susceptible. Administrators should check the theme version displayed in the WordPress dashboard and upgrade if it falls into this range.
Risk and Exploitability
The CVSS score of 9.3 indicates a high severity risk, and with the EPSS score below 1% the current threat of exploitation is low. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread known attacks yet. It is likely that exploitation would occur via a crafted request to the theme’s input handling routines, such as form submissions or URL parameters, which developers need to sanitize properly.
OpenCVE Enrichment
EUVD