Impact
The AutomatorWP plug‑in is vulnerable to a time‑based SQL injection that is triggered through the field_conditions parameter. An attacker who is authenticated with Administrator privileges can inject additional SQL statements into existing queries, allowing the extraction of sensitive database data. The vulnerability specifically exists in all releases up to and including 5.2.3 because the parameter is not properly escaped and the SQL query lacks sufficient preparation.
Affected Systems
The affected product is AutomatorWP – Automator plugin for no‑code automations, webhooks and custom integrations in WordPress. All versions up to 5.2.3, inclusive, are vulnerable. Administrators may have granted this capability to authors or higher roles, expanding the potential impact to those users.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.2, indicating high severity. At the time of analysis the EPSS score is below 1%, suggesting a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Because the attack requires authenticated access with Administrator or higher privileges, the attack vector is limited to users who can log into the WordPress site with such roles; however, the plugin can be configured to expose the functionality to authors, which would broaden the risk.
OpenCVE Enrichment
EUVD