Impact
This vulnerability arises from improper neutralization of special elements used in an SQL command in the Miraculous WordPress theme. An attacker can send crafted input that causes blind SQL injection, allowing them to retrieve, modify, or delete data from the database. The flaw can compromise the confidentiality and integrity of the site’s information, and potentially impact availability if the database is corrupted.
Affected Systems
The issue affects the Miraculous theme from Kamleshyadav, specifically any version prior to 2.0.9. Users employing older releases of this theme on WordPress sites are vulnerable.
Risk and Exploitability
With a CVSS score of 9.3 the vulnerability is considered critical, while the EPSS score of less than 1% indicates a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. The likely attack path is through any input field or URL processed by the theme, where an attacker can inject blind SQL payloads. Successful exploitation would require the attacker to be able to observe side‑effects such as timing or error responses to confirm the injection.
OpenCVE Enrichment
EUVD