Impact
The vulnerability is an SQL injection flaw in the Video List Manager plugin for WordPress, caused by improper neutralization of special elements used in an SQL command. An attacker who can supply crafted input can execute arbitrary SQL statements within the context of the stored database, potentially retrieving, modifying, or deleting data.
Affected Systems
The flaw affects installations of the Video List Manager plugin from unspecified initial releases up to and including version 1.7, which is distributed by the vendor thanhtungtnt.
Risk and Exploitability
The CVSS score of 8.5 reflects high impact, while the EPSS score of less than 1% indicates a low probability of exploitation at present; the vulnerability is not listed in the CISA KEV catalog. Based on the description it is inferred that the attack vector requires injecting harmful SQL via form fields or parameters that are concatenated directly into queries without adequate sanitization, allowing a remote user to execute arbitrary database commands.
OpenCVE Enrichment
EUVD