Impact
The vulnerability is an SQL injection flaw (CWE‑89) in the Iqonic Design WP Roadmap plugin. It allows an attacker to inject arbitrary SQL commands into the database, potentially leading to data exfiltration, data tampering, or further compromise if the database is exploited beyond the injection.
Affected Systems
WordPress sites that have the WP Roadmap plugin from Iqonic Design installed, with affected versions from the earliest release up to and including 2.1.3.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity, while the EPSS score of less than 1% suggests that the likelihood of exploitation is currently low. The vulnerability is not listed in the CISA KEV catalog. Attackers can likely exploit the flaw by sending crafted requests to the WordPress site hosting the vulnerable plugin; based on the description, it is inferred that the attacker does not need authentication, allowing the attack to be carried out without user credentials, making it highly valuable to threat actors.
OpenCVE Enrichment
EUVD