Impact
QuanticaLabs GymBase Theme Classes gymbase_classes plugin contains an improper handling of user input that permits SQL Injection. The flaw enables an attacker to inject arbitrary SQL commands, potentially granting unauthorized data access or modification and compromising database integrity and confidentiality.
Affected Systems
Any WordPress site running the GymBase Theme Classes plugin version 1.4 or earlier is vulnerable. The vulnerability applies to all installations of the plugin up to, and including, version 1.4.
Risk and Exploitability
The CVSS score of 8.5 indicates a high-severity risk. The EPSS score of less than 1% suggests that exploitation is currently uncommon, and the vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector is remote via web requests containing malicious input targeting the plugin. An attacker would need to supply crafted data, either through public forms or injecting through the admin interface, to exploit the flaw. Successful exploitation could lead to uncontrolled data access or alteration, but would require network access to the WordPress instance.
OpenCVE Enrichment
EUVD