Impact
The HieCOR Payment Gateway Plugin contains an improper neutralization of special elements in SQL commands, allowing attackers to inject arbitrary SQL through the plugin’s input fields. Such injection could grant unauthorized data access or modification, compromising confidentiality, integrity, and availability of the WordPress site.
Affected Systems
WordPress sites running the HieCOR Payment Gateway Plugin version 1.5.11 or earlier are affected. All installations of this plugin at those versions are at risk.
Risk and Exploitability
With a CVSS score of 9.3 the flaw is critical. The EPSS score of less than 1% indicates that, while exploitation is possible, it is currently considered very unlikely in the wild. The vulnerability is not listed in CISA’s KEV catalog. Attackers would likely exploit the vulnerability through the plugin’s web interface on an exposed WordPress site, without needing prior authentication. The impact could lead to data exfiltration or further compromise of the database.
OpenCVE Enrichment