Impact
The DirectIQ Email Marketing plugin contains an improper neutralization of special elements in an SQL command, creating an SQL injection flaw. This weakness allows an attacker to inject arbitrary SQL through poorly sanitized input, potentially enabling the reading, modification, or deletion of database records. The impact can compromise the entire WordPress site's data and user information. The issue is identified as CWE‑89.
Affected Systems
The vulnerability affects the DirectIQ Email Marketing WordPress plugin from its earliest release up through version 2.0. No other products are listed, and all releases with a version number less than or equal to 2.0 are affected.
Risk and Exploitability
The flaw carries a CVSS score of 9.3, indicating critical severity, while the EPSS score of less than 1% suggests a low current exploitation probability. The CVE is not listed in the CISA KEV catalog. Attackers can target any WordPress site running the vulnerable plugin by sending malicious input to exposed endpoints, likely without the need for prior authentication. Successful exploitation would have a devastating impact on confidentiality and integrity of the site data.
OpenCVE Enrichment
EUVD