Impact
The Video List Manager plugin contains an SQL Injection flaw where special characters are not properly neutralized before being incorporated into database queries. An attacker could exploit this flaw by sending crafted input to the plugin and execute arbitrary SQL statements, potentially exposing or altering sensitive data stored in the WordPress database.
Affected Systems
The vulnerability affects the WordPress Video List Manager plugin developed by thanhtungtnt, specifically all releases up to and including version 1.7.
Risk and Exploitability
The flaw scores a CVSS of 9.3, indicating critical severity, and the EPSS predicts a very low exploitation probability (<1%). It is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through the plugin’s web interface where input parameters are passed to the database without proper sanitization. The exact authentication requirements are not stated, so the potential for exploitation remains uncertain but should be treated as a high‑risk vulnerability for any site that has the plugin installed.
OpenCVE Enrichment
EUVD