Impact
The WP-Addpub plugin for WordPress, versions up to 1.2.8, contains an SQL Injection flaw triggered by the 'wp-addpub' shortcode. The plugin fails to escape the user-supplied parameter and does not prepare the SQL statement, enabling an attacker with Contributor‑level access or higher to inject additional SQL queries into existing database calls. This can result in the exfiltration of sensitive data from the WordPress database, compromising confidentiality.
Affected Systems
WordPress sites using the WP‑Addpub plugin (vendor cyberscorp) with any release version 1.2.8 or earlier are affected. No further version specifics are listed.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5, indicating moderate severity, and an EPSS score of less than 1%, implying a low current exploitation probability. It is not listed in CISA’s KEV catalog. The likely attack vector involves an authenticated user embedding a malicious shortcode within a post or page; the bounty of data extraction hinges on the attacker’s ability to contribute content to the site.
OpenCVE Enrichment
EUVD